Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 4 556

Количество 4 556

github логотип

GHSA-x5gq-3gjr-236f

около 3 лет назад

Cross-site scripting (XSS) vulnerability in GitLab Enterprise Edition (EE) 6.6.0 before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-x56g-74q4-x3xc

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for users reviewing code changes.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-x4w8-chvq-ph4x

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintentionally allowed group maintainers to view and edit group runner settings.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-x4jh-5c6x-h92v

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

CVSS3: 10
EPSS: Критический
github логотип

GHSA-x4h7-gg27-pw2v

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-x34v-2x5g-pxw5

около 3 лет назад

Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleading content which could trick unsuspecting users into executing arbitrary commands

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-x2v6-6q9m-6qx9

больше 1 года назад

An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-x262-3pxm-ffg9

около 3 лет назад

An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

EPSS: Низкий
github логотип

GHSA-x248-p532-m7g5

около 3 лет назад

GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or potentially other vulnerabilities via unescaped input.

EPSS: Низкий
github логотип

GHSA-wxxw-9mfc-32jr

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.

EPSS: Низкий
github логотип

GHSA-wxm8-9v8q-cpxr

около 2 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-wxhf-x7mr-5gwp

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure of private milestones, labels, and other information.

EPSS: Низкий
github логотип

GHSA-wxgf-f29q-qj6m

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.11 through 12.0.2. When an admin enabled one of the service templates, it was triggering an action that leads to resource depletion. It allows Uncontrolled Resource Consumption.

EPSS: Низкий
github логотип

GHSA-wx3j-3x93-528x

около 3 лет назад

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-wx3g-p9w5-pp6m

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's Asana integration allowed an attacker to potentially cause a regular expression denial of service by sending specially crafted requests.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-wx2f-993h-v22p

около 3 лет назад

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-ww9f-vr49-c3pf

около 3 лет назад

In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wvv5-79h5-39g9

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.

EPSS: Низкий
github логотип

GHSA-wvgj-pjc7-8fc4

около 3 лет назад

A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-wrr4-j76w-2847

около 3 лет назад

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-x5gq-3gjr-236f

Cross-site scripting (XSS) vulnerability in GitLab Enterprise Edition (EE) 6.6.0 before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-x56g-74q4-x3xc

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for users reviewing code changes.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-x4w8-chvq-ph4x

An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintentionally allowed group maintainers to view and edit group runner settings.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-x4jh-5c6x-h92v

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

CVSS3: 10
93%
Критический
около 2 лет назад
github логотип
GHSA-x4h7-gg27-pw2v

An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-x34v-2x5g-pxw5

Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleading content which could trick unsuspecting users into executing arbitrary commands

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-x2v6-6q9m-6qx9

An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-x262-3pxm-ffg9

An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

0%
Низкий
около 3 лет назад
github логотип
GHSA-x248-p532-m7g5

GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or potentially other vulnerabilities via unescaped input.

0%
Низкий
около 3 лет назад
github логотип
GHSA-wxxw-9mfc-32jr

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.

0%
Низкий
около 3 лет назад
github логотип
GHSA-wxm8-9v8q-cpxr

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-wxhf-x7mr-5gwp

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure of private milestones, labels, and other information.

0%
Низкий
около 3 лет назад
github логотип
GHSA-wxgf-f29q-qj6m

An issue was discovered in GitLab Community and Enterprise Edition 11.11 through 12.0.2. When an admin enabled one of the service templates, it was triggering an action that leads to resource depletion. It allows Uncontrolled Resource Consumption.

0%
Низкий
около 3 лет назад
github логотип
GHSA-wx3j-3x93-528x

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

0%
Низкий
около 3 лет назад
github логотип
GHSA-wx3g-p9w5-pp6m

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's Asana integration allowed an attacker to potentially cause a regular expression denial of service by sending specially crafted requests.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-wx2f-993h-v22p

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-ww9f-vr49-c3pf

In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-wvv5-79h5-39g9

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.

0%
Низкий
около 3 лет назад
github логотип
GHSA-wvgj-pjc7-8fc4

A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-wrr4-j76w-2847

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу