Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 4 569

Количество 4 569

ubuntu логотип

CVE-2019-15594

больше 5 лет назад

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-15594

больше 5 лет назад

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-15594

больше 5 лет назад

GitLab 11.8 and later contains a security vulnerability that allows a ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-15593

больше 5 лет назад

GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Issue Comments.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-15593

больше 5 лет назад

GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Issue Comments.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-15593

больше 5 лет назад

GitLab 12.2.3 contains a security vulnerability that allows a user to ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-15592

больше 5 лет назад

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-15592

больше 5 лет назад

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-15592

больше 5 лет назад

GitLab 12.2.2 and below contains a security vulnerability that allows ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-15591

больше 5 лет назад

An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-15591

больше 5 лет назад

An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-15591

больше 5 лет назад

An improper access control vulnerability exists in GitLab <12.3.3 that ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-15590

больше 5 лет назад

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-15590

больше 5 лет назад

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-15590

больше 5 лет назад

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 fo ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-15589

больше 5 лет назад

An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-15589

больше 5 лет назад

An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-15589

больше 5 лет назад

An improper access control vulnerability exists in Gitlab <v12.3.2, <v ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-15586

больше 5 лет назад

A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-15586

больше 5 лет назад

A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-15594

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-15594

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-15594

GitLab 11.8 and later contains a security vulnerability that allows a ...

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-15593

GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Issue Comments.

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-15593

GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Issue Comments.

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-15593

GitLab 12.2.3 contains a security vulnerability that allows a user to ...

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-15592

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

CVSS3: 4.3
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-15592

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

CVSS3: 4.3
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-15592

GitLab 12.2.2 and below contains a security vulnerability that allows ...

CVSS3: 4.3
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-15591

An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-15591

An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-15591

An improper access control vulnerability exists in GitLab <12.3.3 that ...

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-15590

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-15590

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-15590

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 fo ...

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-15589

An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.

CVSS3: 8.8
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-15589

An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.

CVSS3: 8.8
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-15589

An improper access control vulnerability exists in Gitlab <v12.3.2, <v ...

CVSS3: 8.8
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-15586

A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.

CVSS3: 6.1
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-15586

A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.

CVSS3: 6.1
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу