Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 531

Количество 5 531

ubuntu логотип

CVE-2019-6784

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 1 of 2). Markdown fields contain a lack of input validation and output encoding when processing KaTeX that results in a persistent XSS.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-6784

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 1 of 2). Markdown fields contain a lack of input validation and output encoding when processing KaTeX that results in a persistent XSS.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-6784

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-6783

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. GitLab Pages contains a directory traversal vulnerability that could lead to remote command execution.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-6783

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. GitLab Pages contains a directory traversal vulnerability that could lead to remote command execution.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-6783

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-6782

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 1 of 6). An authorization issue allows the contributed project information of a private profile to be viewed.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-6782

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 1 of 6). An authorization issue allows the contributed project information of a private profile to be viewed.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-6782

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-6781

почти 7 лет назад

An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-6781

почти 7 лет назад

An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-6781

почти 7 лет назад

An Improper Input Validation issue was discovered in GitLab Community ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-6240

около 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-6240

около 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-6240

около 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-5883

почти 7 лет назад

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2019-5883

почти 7 лет назад

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2019-5883

почти 7 лет назад

An Incorrect Access Control issue was discovered in GitLab Community a ...

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2019-5487

больше 6 лет назад

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-5487

больше 6 лет назад

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-6784

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 1 of 2). Markdown fields contain a lack of input validation and output encoding when processing KaTeX that results in a persistent XSS.

CVSS3: 6.1
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-6784

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 1 of 2). Markdown fields contain a lack of input validation and output encoding when processing KaTeX that results in a persistent XSS.

CVSS3: 6.1
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-6784

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.1
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-6783

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. GitLab Pages contains a directory traversal vulnerability that could lead to remote command execution.

CVSS3: 8.8
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-6783

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. GitLab Pages contains a directory traversal vulnerability that could lead to remote command execution.

CVSS3: 8.8
2%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-6783

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 8.8
2%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-6782

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 1 of 6). An authorization issue allows the contributed project information of a private profile to be viewed.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-6782

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 1 of 6). An authorization issue allows the contributed project information of a private profile to be viewed.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-6782

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-6781

An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.

CVSS3: 7.5
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-6781

An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.

CVSS3: 7.5
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-6781

An Improper Input Validation issue was discovered in GitLab Community ...

CVSS3: 7.5
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-6240

An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal.

CVSS3: 7.5
0%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-6240

An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal.

CVSS3: 7.5
0%
Низкий
около 7 лет назад
debian логотип
CVE-2019-6240

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
0%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2019-5883

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

CVSS3: 9.1
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-5883

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

CVSS3: 9.1
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-5883

An Incorrect Access Control issue was discovered in GitLab Community a ...

CVSS3: 9.1
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-5487

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

CVSS3: 5.3
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-5487

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

CVSS3: 5.3
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу