Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 4 564

Количество 4 564

nvd логотип

CVE-2018-19574

почти 6 лет назад

GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in the OAuth authorization page.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-19574

почти 6 лет назад

GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4 ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2018-19573

почти 6 лет назад

GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via Mermaid.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-19573

почти 6 лет назад

GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via Mermaid.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-19573

почти 6 лет назад

GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11. ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2018-19572

почти 6 лет назад

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2018-19572

почти 6 лет назад

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2018-19572

почти 6 лет назад

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-c ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2018-19571

почти 6 лет назад

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

CVSS3: 7.7
EPSS: Средний
nvd логотип

CVE-2018-19571

почти 6 лет назад

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

CVSS3: 7.7
EPSS: Средний
debian логотип

CVE-2018-19571

почти 6 лет назад

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11. ...

CVSS3: 7.7
EPSS: Средний
ubuntu логотип

CVE-2018-19570

почти 6 лет назад

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-19570

почти 6 лет назад

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-19570

почти 6 лет назад

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11 ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2018-19569

почти 6 лет назад

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-19569

почти 6 лет назад

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-19569

почти 6 лет назад

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4 ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2018-19496

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-19496

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-19496

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-19574

GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in the OAuth authorization page.

CVSS3: 5.4
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2018-19574

GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4 ...

CVSS3: 5.4
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2018-19573

GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via Mermaid.

CVSS3: 5.4
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2018-19573

GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via Mermaid.

CVSS3: 5.4
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2018-19573

GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11. ...

CVSS3: 5.4
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2018-19572

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

CVSS3: 5.9
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2018-19572

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

CVSS3: 5.9
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2018-19572

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-c ...

CVSS3: 5.9
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2018-19571

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

CVSS3: 7.7
33%
Средний
почти 6 лет назад
nvd логотип
CVE-2018-19571

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

CVSS3: 7.7
33%
Средний
почти 6 лет назад
debian логотип
CVE-2018-19571

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11. ...

CVSS3: 7.7
33%
Средний
почти 6 лет назад
ubuntu логотип
CVE-2018-19570

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVSS3: 5.4
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2018-19570

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVSS3: 5.4
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2018-19570

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11 ...

CVSS3: 5.4
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2018-19569

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2018-19569

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2018-19569

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4 ...

CVSS3: 8.8
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2018-19496

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.

CVSS3: 6.5
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2018-19496

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.

CVSS3: 6.5
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2018-19496

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 6.5
0%
Низкий
почти 6 лет назад

Уязвимостей на страницу