Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-jr4h-pv5f-qr33

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

EPSS: Низкий
github логотип

GHSA-jqw6-r3pp-rfvr

17 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API credentials under certain conditions.

CVSS3: 2.2
EPSS: Низкий
github логотип

GHSA-jqqw-x8w5-v4hh

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-jqf5-5c3v-wj97

почти 4 года назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project.

EPSS: Низкий
github логотип

GHSA-jpgp-p76h-hmp8

почти 4 года назад

An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored XSS by in the error tracking feature.

EPSS: Низкий
github логотип

GHSA-jp4w-5rwv-5wmh

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible to trigger a resource depletion attack due to improper filtering for number of requests to read commits details.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-jmw9-579m-cw2x

почти 4 года назад

OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow

EPSS: Низкий
github логотип

GHSA-jmj3-p7rq-pq5q

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. This vulnerability allows for bypassing the 'group ip restriction' settings to access environment details of projects

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-jm36-4mv9-x2pw

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-jjj8-598g-q254

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.7.7 and 11.8.x before 11.8.3. It allows Information Disclosure.

EPSS: Низкий
github логотип

GHSA-jj7w-rgj3-p8jw

около 1 года назад

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive authentication information.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-jhg6-6fpm-5p2r

почти 4 года назад

A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources.

EPSS: Низкий
github логотип

GHSA-jh26-hqr4-2cjg

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-jgpj-vfxg-97h5

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-jgp3-92wq-g4pq

5 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to trigger unauthorized pipeline executions by manipulating commits.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-jg83-cqm8-3pp5

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-jg7j-6r85-5w9p

почти 4 года назад

GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.

EPSS: Низкий
github логотип

GHSA-jg7h-cr7w-5fc6

больше 3 лет назад

An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-jg4r-vvqm-988m

почти 4 года назад

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-jcwq-43pm-wp74

почти 4 года назад

Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-jr4h-pv5f-qr33

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

0%
Низкий
почти 4 года назад
github логотип
GHSA-jqw6-r3pp-rfvr

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API credentials under certain conditions.

CVSS3: 2.2
0%
Низкий
17 дней назад
github логотип
GHSA-jqqw-x8w5-v4hh

An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.

CVSS3: 2.7
0%
Низкий
10 месяцев назад
github логотип
GHSA-jqf5-5c3v-wj97

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project.

0%
Низкий
почти 4 года назад
github логотип
GHSA-jpgp-p76h-hmp8

An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored XSS by in the error tracking feature.

0%
Низкий
почти 4 года назад
github логотип
GHSA-jp4w-5rwv-5wmh

An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible to trigger a resource depletion attack due to improper filtering for number of requests to read commits details.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-jmw9-579m-cw2x

OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow

0%
Низкий
почти 4 года назад
github логотип
GHSA-jmj3-p7rq-pq5q

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. This vulnerability allows for bypassing the 'group ip restriction' settings to access environment details of projects

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-jm36-4mv9-x2pw

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-jjj8-598g-q254

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.7.7 and 11.8.x before 11.8.3. It allows Information Disclosure.

0%
Низкий
почти 4 года назад
github логотип
GHSA-jj7w-rgj3-p8jw

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive authentication information.

CVSS3: 4.4
0%
Низкий
около 1 года назад
github логотип
GHSA-jhg6-6fpm-5p2r

A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources.

0%
Низкий
почти 4 года назад
github логотип
GHSA-jh26-hqr4-2cjg

An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-jgpj-vfxg-97h5

An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-jgp3-92wq-g4pq

GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to trigger unauthorized pipeline executions by manipulating commits.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-jg83-cqm8-3pp5

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-jg7j-6r85-5w9p

GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.

0%
Низкий
почти 4 года назад
github логотип
GHSA-jg7h-cr7w-5fc6

An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-jg4r-vvqm-988m

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

1%
Низкий
почти 4 года назад
github логотип
GHSA-jcwq-43pm-wp74

Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу