Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

ubuntu логотип

CVE-2019-5883

больше 6 лет назад

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2019-5883

больше 6 лет назад

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2019-5883

больше 6 лет назад

An Incorrect Access Control issue was discovered in GitLab Community a ...

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2019-5487

около 6 лет назад

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-5487

около 6 лет назад

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-5487

около 6 лет назад

An improper access control vulnerability exists in Gitlab EE <v12.3.3, ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2019-5486

около 6 лет назад

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-5486

около 6 лет назад

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-5486

около 6 лет назад

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-5474

около 6 лет назад

An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-5474

около 6 лет назад

An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-5474

около 6 лет назад

An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-5473

больше 6 лет назад

An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2019-5473

больше 6 лет назад

An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.

CVSS3: 7.2
EPSS: Низкий
debian логотип

CVE-2019-5473

больше 6 лет назад

An authentication issue was discovered in GitLab that allowed a bypass ...

CVSS3: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2019-5472

около 6 лет назад

An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-5472

около 6 лет назад

An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-5472

около 6 лет назад

An authorization issue was discovered in Gitlab versions < 12.1.2, < 1 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-5471

больше 6 лет назад

An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-5471

больше 6 лет назад

An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-5883

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

CVSS3: 9.1
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-5883

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

CVSS3: 9.1
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-5883

An Incorrect Access Control issue was discovered in GitLab Community a ...

CVSS3: 9.1
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-5487

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

CVSS3: 5.3
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-5487

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

CVSS3: 5.3
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-5487

An improper access control vulnerability exists in Gitlab EE <v12.3.3, ...

CVSS3: 5.3
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-5486

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

CVSS3: 8.8
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-5486

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

CVSS3: 8.8
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-5486

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, ...

CVSS3: 8.8
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-5474

An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.

CVSS3: 6.5
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-5474

An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.

CVSS3: 6.5
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-5474

An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, ...

CVSS3: 6.5
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-5473

An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.

CVSS3: 7.2
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-5473

An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.

CVSS3: 7.2
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-5473

An authentication issue was discovered in GitLab that allowed a bypass ...

CVSS3: 7.2
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-5472

An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-5472

An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-5472

An authorization issue was discovered in Gitlab versions < 12.1.2, < 1 ...

CVSS3: 7.5
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-5471

An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-5471

An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу