Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 332

Количество 5 332

github логотип

GHSA-jxx7-c7v6-wh2p

27 дней назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces by manipulating namespace identifiers in API requests.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-jx85-pcwq-c9wc

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 12.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-jwfx-6cm3-63qg

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-jvc7-79q4-7754

больше 3 лет назад

In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.

EPSS: Низкий
github логотип

GHSA-jrrv-jm33-8jrv

больше 3 лет назад

Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-jrjm-wgrh-4c93

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration.. It has Insecure Permissions (issue 1 of 4).

EPSS: Низкий
github логотип

GHSA-jr4h-pv5f-qr33

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

EPSS: Низкий
github логотип

GHSA-jqqw-x8w5-v4hh

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-jqf5-5c3v-wj97

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project.

EPSS: Низкий
github логотип

GHSA-jpgp-p76h-hmp8

больше 3 лет назад

An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored XSS by in the error tracking feature.

EPSS: Низкий
github логотип

GHSA-jp4w-5rwv-5wmh

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible to trigger a resource depletion attack due to improper filtering for number of requests to read commits details.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-jmw9-579m-cw2x

больше 3 лет назад

OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow

EPSS: Низкий
github логотип

GHSA-jmj3-p7rq-pq5q

почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. This vulnerability allows for bypassing the 'group ip restriction' settings to access environment details of projects

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-jm36-4mv9-x2pw

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-jjj8-598g-q254

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.7.7 and 11.8.x before 11.8.3. It allows Information Disclosure.

EPSS: Низкий
github логотип

GHSA-jj7w-rgj3-p8jw

11 месяцев назад

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive authentication information.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-jhg6-6fpm-5p2r

больше 3 лет назад

A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources.

EPSS: Низкий
github логотип

GHSA-jh26-hqr4-2cjg

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-jgpj-vfxg-97h5

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-jgp3-92wq-g4pq

3 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to trigger unauthorized pipeline executions by manipulating commits.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-jxx7-c7v6-wh2p

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces by manipulating namespace identifiers in API requests.

CVSS3: 7.1
0%
Низкий
27 дней назад
github логотип
GHSA-jx85-pcwq-c9wc

An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 12.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-jwfx-6cm3-63qg

An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-jvc7-79q4-7754

In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-jrrv-jm33-8jrv

Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-jrjm-wgrh-4c93

An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration.. It has Insecure Permissions (issue 1 of 4).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-jr4h-pv5f-qr33

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-jqqw-x8w5-v4hh

An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.

CVSS3: 2.7
0%
Низкий
9 месяцев назад
github логотип
GHSA-jqf5-5c3v-wj97

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-jpgp-p76h-hmp8

An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored XSS by in the error tracking feature.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-jp4w-5rwv-5wmh

An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible to trigger a resource depletion attack due to improper filtering for number of requests to read commits details.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-jmw9-579m-cw2x

OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow

0%
Низкий
больше 3 лет назад
github логотип
GHSA-jmj3-p7rq-pq5q

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. This vulnerability allows for bypassing the 'group ip restriction' settings to access environment details of projects

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-jm36-4mv9-x2pw

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-jjj8-598g-q254

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.7.7 and 11.8.x before 11.8.3. It allows Information Disclosure.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-jj7w-rgj3-p8jw

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive authentication information.

CVSS3: 4.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-jhg6-6fpm-5p2r

A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-jh26-hqr4-2cjg

An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-jgpj-vfxg-97h5

An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.

CVSS3: 4.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-jgp3-92wq-g4pq

GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to trigger unauthorized pipeline executions by manipulating commits.

CVSS3: 6.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу