Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 531

Количество 5 531

ubuntu логотип

CVE-2019-7353

почти 7 лет назад

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to an authorization issue that allowed users to view confidential issue and merge request titles of other projects.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2019-7353

почти 7 лет назад

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to an authorization issue that allowed users to view confidential issue and merge request titles of other projects.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2019-7353

почти 7 лет назад

An Incorrect Access Control issue was discovered in GitLab Community a ...

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2019-7176

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2019-7176

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2019-7176

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2019-7155

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. A user retains their role within a project in a private group after being removed from the group, if their privileges within the project are different from the group.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-7155

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. A user retains their role within a project in a private group after being removed from the group, if their privileges within the project are different from the group.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-7155

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-6997

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge request titles.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-6997

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge request titles.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-6997

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-6996

больше 6 лет назад

An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers to view membership of private groups.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-6996

больше 6 лет назад

An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers to view membership of private groups.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-6996

больше 6 лет назад

An issue was discovered in GitLab Enterprise Edition 10.x (starting in ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-6995

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-6995

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-6995

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-6960

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-6960

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-7353

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to an authorization issue that allowed users to view confidential issue and merge request titles of other projects.

CVSS3: 9.1
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-7353

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to an authorization issue that allowed users to view confidential issue and merge request titles of other projects.

CVSS3: 9.1
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-7353

An Incorrect Access Control issue was discovered in GitLab Community a ...

CVSS3: 9.1
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-7176

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

CVSS3: 3.7
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-7176

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

CVSS3: 3.7
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-7176

An issue was discovered in GitLab Community and Enterprise Edition 8.x ...

CVSS3: 3.7
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-7155

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. A user retains their role within a project in a private group after being removed from the group, if their privileges within the project are different from the group.

CVSS3: 6.5
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-7155

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. A user retains their role within a project in a private group after being removed from the group, if their privileges within the project are different from the group.

CVSS3: 6.5
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-7155

An issue was discovered in GitLab Community and Enterprise Edition 9.x ...

CVSS3: 6.5
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-6997

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge request titles.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-6997

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge request titles.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-6997

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-6996

An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers to view membership of private groups.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-6996

An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers to view membership of private groups.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-6996

An issue was discovered in GitLab Enterprise Edition 10.x (starting in ...

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-6995

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-6995

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-6995

An issue was discovered in GitLab Community and Enterprise Edition 8.x ...

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-6960

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled.

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-6960

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled.

CVSS3: 9.8
1%
Низкий
больше 6 лет назад

Уязвимостей на страницу