Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

debian логотип

CVE-2020-26413

около 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
EPSS: Критический
ubuntu логотип

CVE-2020-26412

около 5 лет назад

Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2020-26412

около 5 лет назад

Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2020-26412

около 5 лет назад

Removed group members were able to use the To-Do functionality to retr ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2020-26411

около 5 лет назад

A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-26411

около 5 лет назад

A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-26411

около 5 лет назад

A potential DOS vulnerability was discovered in all versions of Gitlab ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2020-26409

около 5 лет назад

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-26409

около 5 лет назад

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-26409

около 5 лет назад

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13 ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2020-26408

около 5 лет назад

A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-26408

около 5 лет назад

A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-26408

около 5 лет назад

A limited information disclosure vulnerability exists in Gitlab CE/EE ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-26407

около 5 лет назад

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2020-26407

около 5 лет назад

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2020-26407

около 5 лет назад

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13 ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2020-26406

около 5 лет назад

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-26406

около 5 лет назад

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-26406

около 5 лет назад

Certain SAST CiConfiguration information could be viewed by unauthoriz ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-26405

около 5 лет назад

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2020-26413

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
93%
Критический
около 5 лет назад
ubuntu логотип
CVE-2020-26412

Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.

CVSS3: 3.1
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-26412

Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.

CVSS3: 3.1
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-26412

Removed group members were able to use the To-Do functionality to retr ...

CVSS3: 3.1
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-26411

A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.

CVSS3: 4.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-26411

A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.

CVSS3: 4.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-26411

A potential DOS vulnerability was discovered in all versions of Gitlab ...

CVSS3: 4.3
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-26409

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

CVSS3: 4.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-26409

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

CVSS3: 4.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-26409

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13 ...

CVSS3: 4.3
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-26408

A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile

CVSS3: 5.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-26408

A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile

CVSS3: 5.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-26408

A limited information disclosure vulnerability exists in Gitlab CE/EE ...

CVSS3: 5.3
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-26407

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

CVSS3: 5.5
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-26407

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

CVSS3: 5.5
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-26407

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13 ...

CVSS3: 5.5
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-26406

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 5.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-26406

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 5.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-26406

Certain SAST CiConfiguration information could be viewed by unauthoriz ...

CVSS3: 5.3
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-26405

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.1
1%
Низкий
около 5 лет назад

Уязвимостей на страницу