Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

nvd логотип

CVE-2020-26405

около 5 лет назад

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2020-26405

около 5 лет назад

Path traversal vulnerability in package upload functionality in GitLab ...

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2020-15525

больше 5 лет назад

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-15525

больше 5 лет назад

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-13359

около 5 лет назад

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2020-13359

около 5 лет назад

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2020-13359

около 5 лет назад

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage si ...

CVSS3: 7.6
EPSS: Низкий
ubuntu логотип

CVE-2020-13358

около 5 лет назад

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2020-13358

около 5 лет назад

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2020-13358

около 5 лет назад

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE v ...

CVSS3: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2020-13357

около 5 лет назад

An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-13357

около 5 лет назад

An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-13357

около 5 лет назад

An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, > ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2020-13356

около 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain specific paths on the server. Affected versions are: >=8.8.9, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2020-13356

около 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain specific paths on the server. Affected versions are: >=8.8.9, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2020-13356

около 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2020-13355

около 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server. Affected versions are: >=8.14, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-13355

около 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server. Affected versions are: >=8.14, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-13355

около 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2020-13354

около 5 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-26405

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.1
1%
Низкий
около 5 лет назад
debian логотип
CVE-2020-26405

Path traversal vulnerability in package upload functionality in GitLab ...

CVSS3: 7.1
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-15525

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-15525

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of ...

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-13359

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.6
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-13359

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.6
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-13359

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage si ...

CVSS3: 7.6
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-13358

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

CVSS3: 4.7
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-13358

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

CVSS3: 4.7
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-13358

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE v ...

CVSS3: 4.7
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-13357

An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

CVSS3: 4.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-13357

An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

CVSS3: 4.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-13357

An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, > ...

CVSS3: 4.3
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-13356

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain specific paths on the server. Affected versions are: >=8.8.9, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 8.2
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-13356

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain specific paths on the server. Affected versions are: >=8.8.9, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 8.2
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-13356

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.2
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-13355

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server. Affected versions are: >=8.14, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.5
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-13355

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server. Affected versions are: >=8.14, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.5
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-13355

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.5
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-13354

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9.

CVSS3: 4.3
1%
Низкий
около 5 лет назад

Уязвимостей на страницу