Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 544

Количество 5 544

ubuntu логотип

CVE-2020-26415

больше 5 лет назад

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-26415

больше 5 лет назад

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-26415

больше 5 лет назад

Information about the starred projects for private user profiles was e ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2020-26414

около 5 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-26414

около 5 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-26414

около 5 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2020-26413

больше 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

CVSS3: 5.3
EPSS: Высокий
nvd логотип

CVE-2020-26413

больше 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

CVSS3: 5.3
EPSS: Высокий
debian логотип

CVE-2020-26413

больше 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
EPSS: Высокий
ubuntu логотип

CVE-2020-26412

больше 5 лет назад

Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2020-26412

больше 5 лет назад

Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2020-26412

больше 5 лет назад

Removed group members were able to use the To-Do functionality to retr ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2020-26411

больше 5 лет назад

A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-26411

больше 5 лет назад

A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-26411

больше 5 лет назад

A potential DOS vulnerability was discovered in all versions of Gitlab ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2020-26409

больше 5 лет назад

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-26409

больше 5 лет назад

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-26409

больше 5 лет назад

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13 ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2020-26408

больше 5 лет назад

A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-26408

больше 5 лет назад

A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-26415

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-26415

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-26415

Information about the starred projects for private user profiles was e ...

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-26414

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

CVSS3: 4.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-26414

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

CVSS3: 4.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-26414

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-26413

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

CVSS3: 5.3
89%
Высокий
больше 5 лет назад
nvd логотип
CVE-2020-26413

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

CVSS3: 5.3
89%
Высокий
больше 5 лет назад
debian логотип
CVE-2020-26413

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
89%
Высокий
больше 5 лет назад
ubuntu логотип
CVE-2020-26412

Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.

CVSS3: 3.1
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-26412

Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.

CVSS3: 3.1
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-26412

Removed group members were able to use the To-Do functionality to retr ...

CVSS3: 3.1
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-26411

A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-26411

A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-26411

A potential DOS vulnerability was discovered in all versions of Gitlab ...

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-26409

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-26409

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-26409

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13 ...

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-26408

A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-26408

A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile

CVSS3: 5.3
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу