Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 544

Количество 5 544

debian логотип

CVE-2020-26408

больше 5 лет назад

A limited information disclosure vulnerability exists in Gitlab CE/EE ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-26407

больше 5 лет назад

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2020-26407

больше 5 лет назад

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2020-26407

больше 5 лет назад

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13 ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2020-26406

больше 5 лет назад

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-26406

больше 5 лет назад

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-26406

больше 5 лет назад

Certain SAST CiConfiguration information could be viewed by unauthoriz ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-26405

больше 5 лет назад

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2020-26405

больше 5 лет назад

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2020-26405

больше 5 лет назад

Path traversal vulnerability in package upload functionality in GitLab ...

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2020-15525

больше 5 лет назад

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-15525

больше 5 лет назад

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-13359

больше 5 лет назад

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2020-13359

больше 5 лет назад

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2020-13359

больше 5 лет назад

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage si ...

CVSS3: 7.6
EPSS: Низкий
ubuntu логотип

CVE-2020-13358

больше 5 лет назад

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2020-13358

больше 5 лет назад

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2020-13358

больше 5 лет назад

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE v ...

CVSS3: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2020-13357

больше 5 лет назад

An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-13357

больше 5 лет назад

An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2020-26408

A limited information disclosure vulnerability exists in Gitlab CE/EE ...

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-26407

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

CVSS3: 5.5
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-26407

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

CVSS3: 5.5
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-26407

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13 ...

CVSS3: 5.5
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-26406

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-26406

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-26406

Certain SAST CiConfiguration information could be viewed by unauthoriz ...

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-26405

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.1
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-26405

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.1
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-26405

Path traversal vulnerability in package upload functionality in GitLab ...

CVSS3: 7.1
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-15525

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-15525

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of ...

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-13359

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.6
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-13359

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.6
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-13359

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage si ...

CVSS3: 7.6
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-13358

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

CVSS3: 4.7
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-13358

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

CVSS3: 4.7
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-13358

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE v ...

CVSS3: 4.7
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-13357

An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-13357

An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

CVSS3: 4.3
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу