Количество 5 918
Количество 5 918
GHSA-p598-8v9q-qjhx
In all versions of GitLab starting from 13.7, marshalled session keys were being stored in Redis.
GHSA-p58m-cp94-fm4f
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.
GHSA-p4rh-pv9g-cw9x
Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token
GHSA-p4cp-frqx-5q69
Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 10.8 prior to 14.8.5, and 10.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances
GHSA-p46f-r59p-v4jf
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
GHSA-p3jh-342h-w8hj
Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2
GHSA-p3cx-frrm-35m8
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to gain unauthorized access to confidential issue title created in public projects under certain circumstances.
GHSA-p39m-p32x-h8jq
GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.
GHSA-p38j-fpm5-5w57
An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.
GHSA-p32w-wm8h-w433
An information disclosure issue in GitLab CE/EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.
GHSA-p27q-qvwx-7mg5
An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL.
GHSA-p25q-vv7x-89px
GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.
GHSA-p246-m8pm-4pjp
GitLab CE/EE since version 9.5 allows a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.
GHSA-mxm2-2266-373h
Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the subgroup is transferred
GHSA-mxgw-4fpv-6f32
Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link
GHSA-mxch-5ff5-jp4w
GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.
GHSA-mx9x-fhqg-ggrp
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.
GHSA-mx9j-jf6w-f9h8
An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the blob view feature.
GHSA-mx6m-x365-fxj7
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.
GHSA-mwvc-fhmm-47cq
GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-p598-8v9q-qjhx In all versions of GitLab starting from 13.7, marshalled session keys were being stored in Redis. | 0% Низкий | около 4 лет назад | ||
GHSA-p58m-cp94-fm4f An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-p4rh-pv9g-cw9x Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token | 1% Низкий | около 4 лет назад | ||
GHSA-p4cp-frqx-5q69 Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 10.8 prior to 14.8.5, and 10.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
GHSA-p46f-r59p-v4jf An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before. | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-p3jh-342h-w8hj Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2 | 1% Низкий | около 4 лет назад | ||
GHSA-p3cx-frrm-35m8 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to gain unauthorized access to confidential issue title created in public projects under certain circumstances. | CVSS3: 4.3 | 0% Низкий | 5 месяцев назад | |
GHSA-p39m-p32x-h8jq GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline. | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-p38j-fpm5-5w57 An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users. | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
GHSA-p32w-wm8h-w433 An information disclosure issue in GitLab CE/EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration. | CVSS3: 4.3 | 0% Низкий | почти 3 года назад | |
GHSA-p27q-qvwx-7mg5 An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-p25q-vv7x-89px GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF. | 1% Низкий | около 4 лет назад | ||
GHSA-p246-m8pm-4pjp GitLab CE/EE since version 9.5 allows a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking. | CVSS3: 4.9 | 1% Низкий | около 4 лет назад | |
GHSA-mxm2-2266-373h Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the subgroup is transferred | 1% Низкий | около 4 лет назад | ||
GHSA-mxgw-4fpv-6f32 Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-mxch-5ff5-jp4w GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images. | 1% Низкий | около 4 лет назад | ||
GHSA-mx9x-fhqg-ggrp An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names. | CVSS3: 7.5 | 19% Средний | больше 1 года назад | |
GHSA-mx9j-jf6w-f9h8 An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the blob view feature. | 1% Низкий | около 4 лет назад | ||
GHSA-mx6m-x365-fxj7 An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location. | CVSS3: 7.4 | 1% Низкий | почти 4 года назад | |
GHSA-mwvc-fhmm-47cq GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import. | CVSS3: 8.8 | 4% Низкий | около 4 лет назад |
Уязвимостей на страницу