Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 4 564

Количество 4 564

ubuntu логотип

CVE-2018-9243

около 7 лет назад

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-9243

около 7 лет назад

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-9243

около 7 лет назад

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vu ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-8971

больше 7 лет назад

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2018-8971

больше 7 лет назад

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-8971

больше 7 лет назад

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, a ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2018-8801

около 7 лет назад

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-8801

около 7 лет назад

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-8801

около 7 лет назад

GitLab Community and Enterprise Editions version 8.3 up to 10.x before ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2018-3710

больше 7 лет назад

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2018-3710

больше 7 лет назад

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2018-3710

больше 7 лет назад

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable ...

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2018-20507

больше 5 лет назад

An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2018-20507

больше 5 лет назад

An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2018-20507

больше 5 лет назад

An issue was discovered in GitLab Enterprise Edition 11.2.x through 11 ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2018-20501

больше 5 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2018-20501

больше 5 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2018-20501

больше 5 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2018-20500

около 6 лет назад

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-20500

около 6 лет назад

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-9243

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
0%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-9243

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
0%
Низкий
около 7 лет назад
debian логотип
CVE-2018-9243

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vu ...

CVSS3: 6.1
0%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2018-8971

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS3: 9.8
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-8971

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS3: 9.8
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-8971

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, a ...

CVSS3: 9.8
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-8801

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
0%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-8801

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
0%
Низкий
около 7 лет назад
debian логотип
CVE-2018-8801

GitLab Community and Enterprise Editions version 8.3 up to 10.x before ...

CVSS3: 6.5
0%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2018-3710

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

CVSS3: 7.8
5%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-3710

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

CVSS3: 7.8
5%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-3710

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable ...

CVSS3: 7.8
5%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-20507

An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2018-20507

An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2018-20507

An issue was discovered in GitLab Enterprise Edition 11.2.x through 11 ...

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2018-20501

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS3: 6.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2018-20501

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS3: 6.3
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2018-20501

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.3
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2018-20500

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2018-20500

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

CVSS3: 7.5
0%
Низкий
около 6 лет назад

Уязвимостей на страницу