Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 4 565

Количество 4 565

debian логотип

CVE-2019-11605

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-11549

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-11549

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-11549

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-11548

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-11548

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2019-11548

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2019-11547

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-11547

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-11547

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-11546

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-11546

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-11546

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2019-11545

почти 6 лет назад

An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-11545

почти 6 лет назад

An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-11545

почти 6 лет назад

An issue was discovered in GitLab Community Edition 11.9.x before 11.9 ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-11544

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It allows Information Disclosure. Non-member users who subscribe to notifications of an internal project with issue and repository restrictions will receive emails about restricted events.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-11544

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It allows Information Disclosure. Non-member users who subscribe to notifications of an internal project with issue and repository restrictions will receive emails about restricted events.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-11544

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-11000

около 6 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2019-11605

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-11549

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.

CVSS3: 6.5
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-11549

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.

CVSS3: 6.5
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-11549

An issue was discovered in GitLab Community and Enterprise Edition 9.x ...

CVSS3: 6.5
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-11548

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.

CVSS3: 5.4
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-11548

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.

CVSS3: 5.4
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-11548

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.4
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-11547

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues.

CVSS3: 6.1
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-11547

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues.

CVSS3: 6.1
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-11547

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.1
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-11546

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge.

CVSS3: 5.3
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-11546

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge.

CVSS3: 5.3
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-11546

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.3
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-11545

An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-11545

An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-11545

An issue was discovered in GitLab Community Edition 11.9.x before 11.9 ...

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-11544

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It allows Information Disclosure. Non-member users who subscribe to notifications of an internal project with issue and repository restrictions will receive emails about restricted events.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-11544

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It allows Information Disclosure. Non-member users who subscribe to notifications of an internal project with issue and repository restrictions will receive emails about restricted events.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-11544

An issue was discovered in GitLab Community and Enterprise Edition 8.x ...

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-11000

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

CVSS3: 6.5
1%
Низкий
около 6 лет назад

Уязвимостей на страницу