Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

ubuntu логотип

CVE-2019-15575

около 6 лет назад

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-15575

около 6 лет назад

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-15575

около 6 лет назад

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v1 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-14944

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-14944

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-14944

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-14943

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-14943

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-14943

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12. ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2019-14942

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages (which have access control) could be sent over cleartext HTTP.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2019-14942

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages (which have access control) could be sent over cleartext HTTP.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2019-14942

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2019-13121

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-13121

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-13121

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-13011

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-13011

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-13011

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12 ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-13010

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It allows Uncontrolled Resource Consumption.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2019-13010

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It allows Uncontrolled Resource Consumption.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-15575

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

CVSS3: 7.5
3%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-15575

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

CVSS3: 7.5
3%
Низкий
около 6 лет назад
debian логотип
CVE-2019-15575

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v1 ...

CVSS3: 7.5
3%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-14944

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2019-14944

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
debian логотип
CVE-2019-14944

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.5
1%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2019-14943

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS3: 9.8
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-14943

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS3: 9.8
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-14943

An issue was discovered in GitLab Community and Enterprise Edition 12. ...

CVSS3: 9.8
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-14942

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages (which have access control) could be sent over cleartext HTTP.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2019-14942

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages (which have access control) could be sent over cleartext HTTP.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
debian логотип
CVE-2019-14942

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.9
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2019-13121

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-13121

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-13121

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0 ...

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-13011

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-13011

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-13011

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12 ...

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-13010

An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It allows Uncontrolled Resource Consumption.

CVSS3: 5.9
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-13010

An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It allows Uncontrolled Resource Consumption.

CVSS3: 5.9
0%
Низкий
почти 6 лет назад

Уязвимостей на страницу