Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 4 565

Количество 4 565

nvd логотип

CVE-2019-10113

около 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Making concurrent GET /api/v4/projects/<id>/languages requests may allow Uncontrolled Resource Consumption.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-10113

около 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-10112

около 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The construction of the HMAC key was insecurely derived.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-10112

около 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The construction of the HMAC key was insecurely derived.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-10112

около 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-10111

около 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allows persistent XSS in the merge request "resolve conflicts" page.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-10111

около 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allows persistent XSS in the merge request "resolve conflicts" page.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2019-10111

около 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2019-10110

около 6 лет назад

An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The "move issue" feature may allow a user to create projects under any namespace on any GitLab instance on which they hold credentials.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-10110

около 6 лет назад

An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The "move issue" feature may allow a user to create projects under any namespace on any GitLab instance on which they hold credentials.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-10110

около 6 лет назад

An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-10109

около 6 лет назад

An Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. EXIF geolocation data were not removed from images when uploaded to GitLab. As a result, anyone with access to the uploaded image could obtain its geolocation, device, and software version data (if present).

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-10109

около 6 лет назад

An Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. EXIF geolocation data were not removed from images when uploaded to GitLab. As a result, anyone with access to the uploaded image could obtain its geolocation, device, and software version data (if present).

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-10109

около 6 лет назад

An Information Exposure issue (issue 1 of 2) was discovered in GitLab ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2019-10108

около 6 лет назад

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-10108

около 6 лет назад

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2019-10108

около 6 лет назад

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Co ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2018-9244

около 7 лет назад

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-9244

около 7 лет назад

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-9244

около 7 лет назад

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vu ...

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-10113

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Making concurrent GET /api/v4/projects/<id>/languages requests may allow Uncontrolled Resource Consumption.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-10113

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-10112

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The construction of the HMAC key was insecurely derived.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-10112

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The construction of the HMAC key was insecurely derived.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-10112

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-10111

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allows persistent XSS in the merge request "resolve conflicts" page.

CVSS3: 5.4
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-10111

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allows persistent XSS in the merge request "resolve conflicts" page.

CVSS3: 5.4
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-10111

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.4
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-10110

An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The "move issue" feature may allow a user to create projects under any namespace on any GitLab instance on which they hold credentials.

CVSS3: 6.5
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-10110

An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The "move issue" feature may allow a user to create projects under any namespace on any GitLab instance on which they hold credentials.

CVSS3: 6.5
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-10110

An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab ...

CVSS3: 6.5
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-10109

An Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. EXIF geolocation data were not removed from images when uploaded to GitLab. As a result, anyone with access to the uploaded image could obtain its geolocation, device, and software version data (if present).

CVSS3: 5.3
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-10109

An Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. EXIF geolocation data were not removed from images when uploaded to GitLab. As a result, anyone with access to the uploaded image could obtain its geolocation, device, and software version data (if present).

CVSS3: 5.3
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-10109

An Information Exposure issue (issue 1 of 2) was discovered in GitLab ...

CVSS3: 5.3
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-10108

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels.

CVSS3: 5.4
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-10108

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels.

CVSS3: 5.4
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-10108

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Co ...

CVSS3: 5.4
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2018-9244

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
0%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-9244

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
0%
Низкий
около 7 лет назад
debian логотип
CVE-2018-9244

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vu ...

CVSS3: 6.1
0%
Низкий
около 7 лет назад

Уязвимостей на страницу