Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 918

Количество 5 918

github логотип

GHSA-pg9r-mg67-jxwg

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in markdown could be pointed to an arbitrary server, which would reveal the IP address of clients requesting the file from that server.

EPSS: Низкий
github логотип

GHSA-pfg9-h349-wqvq

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 It was possible to exploit a vulnerability in the external status checks feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-pf2w-vxpr-vvpx

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 3 of 6). For installations using GitHub or Bitbucket OAuth integrations, it is possible to use a covert redirect to obtain the user OAuth token for those services.

EPSS: Низкий
github логотип

GHSA-pcp6-wgmj-c279

около 4 лет назад

GitLab Enterprise Edition (EE) 8.90 and later through 12.5 has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-pcf2-p33r-6879

около 4 лет назад

An issue has been discovered in GitLab affecting versions prior to 13.2.10, 13.3.7 and 13.4.2: Lack of Rate Limiting at Re-Sending Confirmation Email

EPSS: Низкий
github логотип

GHSA-p9w7-rqj5-fjh5

8 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a denial of service condition by uploading specially crafted images.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-p9m7-w29m-489v

около 4 лет назад

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

EPSS: Низкий
github логотип

GHSA-p9cp-qq4c-2wr5

7 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-p96p-59v7-xxp6

около 3 лет назад

A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 4.3
EPSS: Высокий
github логотип

GHSA-p967-h43j-8p83

около 4 лет назад

In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-p95h-29v8-j2h6

почти 4 года назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p932-x66g-q6cc

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper output encoding could lead to XSS if CSP is not enabled.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-p7jp-3g8m-8m7m

около 4 лет назад

A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1

EPSS: Низкий
github логотип

GHSA-p7j7-2wwv-p5hw

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p7gw-xwgf-7w7c

7 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to modify instance-wide AI feature provider settings by exploiting missing authorization checks in GraphQL mutations.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-p79f-679r-6p3w

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-p6pm-7qxv-f8f3

больше 4 лет назад

Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.

EPSS: Низкий
github логотип

GHSA-p66q-2x4m-xxx9

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-p5m4-rr7j-g8gx

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-p5fq-m9jh-pjrv

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to commit to projects even from a restricted IP address.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-pg9r-mg67-jxwg

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in markdown could be pointed to an arbitrary server, which would reveal the IP address of clients requesting the file from that server.

2%
Низкий
около 4 лет назад
github логотип
GHSA-pfg9-h349-wqvq

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 It was possible to exploit a vulnerability in the external status checks feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-pf2w-vxpr-vvpx

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 3 of 6). For installations using GitHub or Bitbucket OAuth integrations, it is possible to use a covert redirect to obtain the user OAuth token for those services.

4%
Низкий
около 4 лет назад
github логотип
GHSA-pcp6-wgmj-c279

GitLab Enterprise Edition (EE) 8.90 and later through 12.5 has Incorrect Access Control.

1%
Низкий
около 4 лет назад
github логотип
GHSA-pcf2-p33r-6879

An issue has been discovered in GitLab affecting versions prior to 13.2.10, 13.3.7 and 13.4.2: Lack of Rate Limiting at Re-Sending Confirmation Email

1%
Низкий
около 4 лет назад
github логотип
GHSA-p9w7-rqj5-fjh5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a denial of service condition by uploading specially crafted images.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-p9m7-w29m-489v

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

1%
Низкий
около 4 лет назад
github логотип
GHSA-p9cp-qq4c-2wr5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.

CVSS3: 8.7
0%
Низкий
7 месяцев назад
github логотип
GHSA-p96p-59v7-xxp6

A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 4.3
84%
Высокий
около 3 лет назад
github логотип
GHSA-p967-h43j-8p83

In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-p95h-29v8-j2h6

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-p932-x66g-q6cc

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper output encoding could lead to XSS if CSP is not enabled.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-p7jp-3g8m-8m7m

A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1

1%
Низкий
около 4 лет назад
github логотип
GHSA-p7j7-2wwv-p5hw

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-p7gw-xwgf-7w7c

GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to modify instance-wide AI feature provider settings by exploiting missing authorization checks in GraphQL mutations.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-p79f-679r-6p3w

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-p6pm-7qxv-f8f3

Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-p66q-2x4m-xxx9

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-p5m4-rr7j-g8gx

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has XSS.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-p5fq-m9jh-pjrv

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to commit to projects even from a restricted IP address.

CVSS3: 6.5
1%
Низкий
около 3 лет назад

Уязвимостей на страницу