Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 918

Количество 5 918

github логотип

GHSA-mmc8-x8mq-826c

около 2 лет назад

A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging this vulnerability, an attacker could exfiltrate anti-CSRF tokens via the Kubernetes Agent Server (KAS).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-mjcr-h6w7-xcx6

почти 4 года назад

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

CVSS3: 9.9
EPSS: Высокий
github логотип

GHSA-mj6c-rwfc-g9jh

23 дня назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with minimal access permissions to read work item metadata from private projects due to missing authorization checks.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-mhvv-m4rg-2pmj

около 4 лет назад

An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The GitLab Releases feature could allow guest users access to private information like release details and code information.

EPSS: Низкий
github логотип

GHSA-mhv3-28f9-6jvj

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-mhr8-wccg-2q8g

23 дня назад

GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to obtain another user's stored credentials due to improper authorization controls.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-mhq2-mq3h-45cg

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member.

EPSS: Низкий
github логотип

GHSA-mh9g-743p-49cw

около 4 лет назад

GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-mgg5-84cv-fc3c

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVSS3: 10
EPSS: Критический
github логотип

GHSA-mgcq-rqq2-gc5f

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause a denial of service condition due to improper input validation on webhook custom header names under certain conditions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-mfcp-rjv7-385m

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-mf63-gqmm-mv3v

около 4 лет назад

GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2).

EPSS: Низкий
github логотип

GHSA-mch5-32hg-65cq

около 4 лет назад

GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.

EPSS: Низкий
github логотип

GHSA-mc42-9p8q-pxff

почти 2 года назад

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration.

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-mc38-g3j7-hgww

около 4 лет назад

It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-m9gh-48vw-5j3h

больше 3 лет назад

An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-m9cp-4p2h-f9p9

почти 2 года назад

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2. When adding a authorizing an application, it can be made to render as HTML under specific circumstances.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-m9c3-9q65-f749

около 4 лет назад

GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups.

EPSS: Низкий
github логотип

GHSA-m99q-r6r6-wxx3

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the server.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-m96m-mfqc-86mf

около 3 лет назад

An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-mmc8-x8mq-826c

A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging this vulnerability, an attacker could exfiltrate anti-CSRF tokens via the Kubernetes Agent Server (KAS).

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-mjcr-h6w7-xcx6

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

CVSS3: 9.9
76%
Высокий
почти 4 года назад
github логотип
GHSA-mj6c-rwfc-g9jh

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with minimal access permissions to read work item metadata from private projects due to missing authorization checks.

CVSS3: 4.3
0%
Низкий
23 дня назад
github логотип
GHSA-mhvv-m4rg-2pmj

An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The GitLab Releases feature could allow guest users access to private information like release details and code information.

1%
Низкий
около 4 лет назад
github логотип
GHSA-mhv3-28f9-6jvj

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.

CVSS3: 3.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-mhr8-wccg-2q8g

GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to obtain another user's stored credentials due to improper authorization controls.

CVSS3: 4.9
0%
Низкий
23 дня назад
github логотип
GHSA-mhq2-mq3h-45cg

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member.

1%
Низкий
около 4 лет назад
github логотип
GHSA-mh9g-743p-49cw

GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.

1%
Низкий
около 4 лет назад
github логотип
GHSA-mgg5-84cv-fc3c

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVSS3: 10
95%
Критический
больше 2 лет назад
github логотип
GHSA-mgcq-rqq2-gc5f

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause a denial of service condition due to improper input validation on webhook custom header names under certain conditions.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-mfcp-rjv7-385m

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-mf63-gqmm-mv3v

GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2).

1%
Низкий
около 4 лет назад
github логотип
GHSA-mch5-32hg-65cq

GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.

1%
Низкий
около 4 лет назад
github логотип
GHSA-mc42-9p8q-pxff

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration.

CVSS3: 4.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-mc38-g3j7-hgww

It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-m9gh-48vw-5j3h

An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-m9cp-4p2h-f9p9

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2. When adding a authorizing an application, it can be made to render as HTML under specific circumstances.

CVSS3: 7.3
2%
Низкий
почти 2 года назад
github логотип
GHSA-m9c3-9q65-f749

GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups.

2%
Низкий
около 4 лет назад
github логотип
GHSA-m99q-r6r6-wxx3

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the server.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-m96m-mfqc-86mf

An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI.

CVSS3: 6.3
1%
Низкий
около 3 лет назад

Уязвимостей на страницу