Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

ubuntu логотип

CVE-2020-6832

около 6 лет назад

An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private projects.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-6832

около 6 лет назад

An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private projects.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-6832

около 6 лет назад

An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 throug ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-5197

около 6 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrect Access Control.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-5197

около 6 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrect Access Control.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-5197

около 6 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterpris ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2020-26417

около 5 лет назад

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-26417

около 5 лет назад

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-26417

около 5 лет назад

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later expo ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-26416

около 5 лет назад

Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

CVSS3: 4
EPSS: Низкий
nvd логотип

CVE-2020-26416

около 5 лет назад

Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

CVSS3: 4
EPSS: Низкий
debian логотип

CVE-2020-26416

около 5 лет назад

Information disclosure in Advanced Search component of GitLab EE start ...

CVSS3: 4
EPSS: Низкий
ubuntu логотип

CVE-2020-26415

около 5 лет назад

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-26415

около 5 лет назад

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-26415

около 5 лет назад

Information about the starred projects for private user profiles was e ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2020-26414

около 5 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-26414

около 5 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-26414

около 5 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2020-26413

около 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

CVSS3: 5.3
EPSS: Критический
nvd логотип

CVE-2020-26413

около 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

CVSS3: 5.3
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-6832

An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private projects.

CVSS3: 5.3
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2020-6832

An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private projects.

CVSS3: 5.3
0%
Низкий
около 6 лет назад
debian логотип
CVE-2020-6832

An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 throug ...

CVSS3: 5.3
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2020-5197

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrect Access Control.

CVSS3: 4.3
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2020-5197

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrect Access Control.

CVSS3: 4.3
0%
Низкий
около 6 лет назад
debian логотип
CVE-2020-5197

An issue was discovered in GitLab Community Edition (CE) and Enterpris ...

CVSS3: 4.3
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2020-26417

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.

CVSS3: 5.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-26417

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.

CVSS3: 5.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-26417

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later expo ...

CVSS3: 5.3
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-26416

Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

CVSS3: 4
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-26416

Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

CVSS3: 4
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-26416

Information disclosure in Advanced Search component of GitLab EE start ...

CVSS3: 4
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-26415

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

CVSS3: 4.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-26415

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

CVSS3: 4.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-26415

Information about the starred projects for private user profiles was e ...

CVSS3: 4.3
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-26414

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

CVSS3: 4.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-26414

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

CVSS3: 4.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-26414

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-26413

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

CVSS3: 5.3
93%
Критический
около 5 лет назад
nvd логотип
CVE-2020-26413

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

CVSS3: 5.3
93%
Критический
около 5 лет назад

Уязвимостей на страницу