Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 4 556

Количество 4 556

github логотип

GHSA-9hhr-gwc7-jcvh

около 3 лет назад

The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.

EPSS: Средний
ubuntu логотип

CVE-2023-5332

больше 1 года назад

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2023-5332

больше 1 года назад

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2023-5332

больше 1 года назад

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2023-5332

больше 1 года назад

Patch in third party library Consul requires 'enable-script-checks' to ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2022-3573

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-3573

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-3573

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2021-32823

почти 4 года назад

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2021-32823

почти 4 года назад

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2021-32823

почти 4 года назад

In the bindata RubyGem before version 2.4.10 there is a potential deni ...

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2013-4583

больше 5 лет назад

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2013-4583

больше 5 лет назад

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4 ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2013-4582

больше 5 лет назад

The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to include information from local files into the metadata of a Git repository via the web interface.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2013-4582

больше 5 лет назад

The (1) create_branch, (2) create_tag, (3) import_project, and (4) for ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2013-4581

около 11 лет назад

GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2013-4581

около 11 лет назад

GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Ed ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-4546

около 11 лет назад

The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2013-4546

около 11 лет назад

The repository import feature in gitlab-shell before 1.7.4, as used in ...

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2013-4490

около 11 лет назад

The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.

CVSS2: 6.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-9hhr-gwc7-jcvh

The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.

48%
Средний
около 3 лет назад
ubuntu логотип
CVE-2023-5332

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2023-5332

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 8.1
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-5332

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-5332

Patch in third party library Consul requires 'enable-script-checks' to ...

CVSS3: 5.9
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2022-3573

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-3573

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-3573

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2021-32823

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.

CVSS3: 3.7
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-32823

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.

CVSS3: 3.7
0%
Низкий
почти 4 года назад
debian логотип
CVE-2021-32823

In the bindata RubyGem before version 2.4.10 there is a potential deni ...

CVSS3: 3.7
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2013-4583

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.

CVSS3: 8.8
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2013-4583

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4 ...

CVSS3: 8.8
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2013-4582

The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to include information from local files into the metadata of a Git repository via the web interface.

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2013-4582

The (1) create_branch, (2) create_tag, (3) import_project, and (4) for ...

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2013-4581

GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.

CVSS2: 6.8
1%
Низкий
около 11 лет назад
debian логотип
CVE-2013-4581

GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Ed ...

CVSS2: 6.8
1%
Низкий
около 11 лет назад
nvd логотип
CVE-2013-4546

The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.

CVSS2: 6.5
0%
Низкий
около 11 лет назад
debian логотип
CVE-2013-4546

The repository import feature in gitlab-shell before 1.7.4, as used in ...

CVSS2: 6.5
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2013-4490

The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.

CVSS2: 6.5
48%
Средний
около 11 лет назад

Уязвимостей на страницу