Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 544

Количество 5 544

ubuntu логотип

CVE-2021-22219

почти 5 лет назад

All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2021-22219

почти 5 лет назад

All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2021-22219

почти 5 лет назад

All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all ver ...

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2021-22218

почти 5 лет назад

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2021-22218

почти 5 лет назад

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2021-22218

почти 5 лет назад

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all ve ...

CVSS3: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2021-22217

почти 5 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-22217

почти 5 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-22217

почти 5 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE befo ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-22216

почти 5 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-22216

почти 5 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-22216

почти 5 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE befo ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-22215

почти 5 лет назад

An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-22215

почти 5 лет назад

An information disclosure vulnerability in GitLab EE versions 13.11 an ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2021-22214

почти 5 лет назад

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

CVSS3: 6.8
EPSS: Критический
nvd логотип

CVE-2021-22214

почти 5 лет назад

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

CVSS3: 6.8
EPSS: Критический
debian логотип

CVE-2021-22214

почти 5 лет назад

When requests to the internal network for webhooks are enabled, a serv ...

CVSS3: 6.8
EPSS: Критический
ubuntu логотип

CVE-2021-22213

почти 5 лет назад

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2021-22213

почти 5 лет назад

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2021-22213

почти 5 лет назад

A cross-site leak vulnerability in the OAuth flow of all versions of G ...

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-22219

All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.

CVSS3: 4.4
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22219

All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.

CVSS3: 4.4
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22219

All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all ver ...

CVSS3: 4.4
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22218

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22218

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22218

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all ve ...

CVSS3: 2.6
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22217

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request

CVSS3: 6.5
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22217

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request

CVSS3: 6.5
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22217

A denial of service vulnerability in all versions of GitLab CE/EE befo ...

CVSS3: 6.5
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22216

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

CVSS3: 6.5
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22216

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

CVSS3: 6.5
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22216

A denial of service vulnerability in all versions of GitLab CE/EE befo ...

CVSS3: 6.5
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22215

An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22215

An information disclosure vulnerability in GitLab EE versions 13.11 an ...

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22214

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

CVSS3: 6.8
93%
Критический
почти 5 лет назад
nvd логотип
CVE-2021-22214

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

CVSS3: 6.8
93%
Критический
почти 5 лет назад
debian логотип
CVE-2021-22214

When requests to the internal network for webhooks are enabled, a serv ...

CVSS3: 6.8
93%
Критический
почти 5 лет назад
ubuntu логотип
CVE-2021-22213

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

CVSS3: 8.8
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22213

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

CVSS3: 8.8
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22213

A cross-site leak vulnerability in the OAuth flow of all versions of G ...

CVSS3: 8.8
1%
Низкий
почти 5 лет назад

Уязвимостей на страницу