Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 918

Количество 5 918

github логотип

GHSA-m8q6-f6pj-j3mh

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-m8p6-xp2q-8w7h

около 4 лет назад

A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion.

EPSS: Низкий
github логотип

GHSA-m8j6-rg22-ww2f

около 4 лет назад

An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-m8gr-q643-3q88

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows deploy keys to push to an archived repository.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-m874-44cm-939v

около 4 лет назад

GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.

EPSS: Низкий
github логотип

GHSA-m7f3-552r-pf23

почти 4 года назад

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-m77g-m5w2-j2f3

около 4 лет назад

GitLab 9.5.9 through 12.9 is vulnerable to stored XSS in an admin notification feature.

EPSS: Низкий
github логотип

GHSA-m766-xfqm-qm37

8 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to bypass WebAuthn two-factor authentication by manipulating the session state under certain conditions.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-m6pw-2x85-c738

около 4 лет назад

In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.

EPSS: Низкий
github логотип

GHSA-m6m2-gm49-gp5r

около 4 лет назад

GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snippet through the API.

EPSS: Низкий
github логотип

GHSA-m668-xfwp-34x6

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service by uploading malicious files.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-m62r-8f87-wrg8

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that under certain conditions could have allowed an authenticated user to cause a denial of service due to improper handling of webhook response data.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-m5gx-r8rq-3635

около 4 лет назад

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The path of a private project, that used to be public, would be disclosed in the unsubscribe email link of issues and merge requests.

EPSS: Низкий
github логотип

GHSA-m4hq-98c3-4xmx

почти 3 года назад

A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-m49f-rvv4-r4rv

23 дня назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-m48m-pq7g-rfh9

около 4 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage.

EPSS: Низкий
github логотип

GHSA-m3c6-4xg4-583x

4 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user to have access to other users' email addresses via certain GraphQL queries.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-m393-h7jj-5g9w

около 4 лет назад

GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Issue Comments.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-m37q-w59j-4vr4

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

CVSS3: 5.3
EPSS: Высокий
github логотип

GHSA-m2g4-fcc3-wp4v

около 4 лет назад

An issue has been discovered in GitLab affecting versions starting with 13.5 up to 13.9.7. Improper permission check could allow the change of timestamp for issue creation or update.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-m8q6-f6pj-j3mh

An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-m8p6-xp2q-8w7h

A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion.

1%
Низкий
около 4 лет назад
github логотип
GHSA-m8j6-rg22-ww2f

An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects

CVSS3: 2.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-m8gr-q643-3q88

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows deploy keys to push to an archived repository.

CVSS3: 4.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-m874-44cm-939v

GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.

1%
Низкий
около 4 лет назад
github логотип
GHSA-m7f3-552r-pf23

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

CVSS3: 8.8
86%
Высокий
почти 4 года назад
github логотип
GHSA-m77g-m5w2-j2f3

GitLab 9.5.9 through 12.9 is vulnerable to stored XSS in an admin notification feature.

1%
Низкий
около 4 лет назад
github логотип
GHSA-m766-xfqm-qm37

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to bypass WebAuthn two-factor authentication by manipulating the session state under certain conditions.

CVSS3: 6.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-m6pw-2x85-c738

In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.

1%
Низкий
около 4 лет назад
github логотип
GHSA-m6m2-gm49-gp5r

GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snippet through the API.

1%
Низкий
около 4 лет назад
github логотип
GHSA-m668-xfwp-34x6

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service by uploading malicious files.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-m62r-8f87-wrg8

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that under certain conditions could have allowed an authenticated user to cause a denial of service due to improper handling of webhook response data.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-m5gx-r8rq-3635

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The path of a private project, that used to be public, would be disclosed in the unsubscribe email link of issues and merge requests.

1%
Низкий
около 4 лет назад
github логотип
GHSA-m4hq-98c3-4xmx

A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

CVSS3: 8.2
1%
Низкий
почти 3 года назад
github логотип
GHSA-m49f-rvv4-r4rv

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.

CVSS3: 7.3
0%
Низкий
23 дня назад
github логотип
GHSA-m48m-pq7g-rfh9

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage.

1%
Низкий
около 4 лет назад
github логотип
GHSA-m3c6-4xg4-583x

GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user to have access to other users' email addresses via certain GraphQL queries.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-m393-h7jj-5g9w

GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Issue Comments.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-m37q-w59j-4vr4

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

CVSS3: 5.3
80%
Высокий
больше 4 лет назад
github логотип
GHSA-m2g4-fcc3-wp4v

An issue has been discovered in GitLab affecting versions starting with 13.5 up to 13.9.7. Improper permission check could allow the change of timestamp for issue creation or update.

CVSS3: 4.3
1%
Низкий
около 4 лет назад

Уязвимостей на страницу