Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

nvd логотип

CVE-2019-11546

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-11546

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2019-11545

больше 6 лет назад

An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-11545

больше 6 лет назад

An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-11545

больше 6 лет назад

An issue was discovered in GitLab Community Edition 11.9.x before 11.9 ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-11544

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It allows Information Disclosure. Non-member users who subscribe to notifications of an internal project with issue and repository restrictions will receive emails about restricted events.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-11544

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It allows Information Disclosure. Non-member users who subscribe to notifications of an internal project with issue and repository restrictions will receive emails about restricted events.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-11544

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-11000

больше 6 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-11000

больше 6 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-11000

больше 6 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 1 ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-10640

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input validation issue for the .gitlab-ci.yml refs value allows Uncontrolled Resource Consumption.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-10640

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input validation issue for the .gitlab-ci.yml refs value allows Uncontrolled Resource Consumption.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-10640

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-10301

почти 7 лет назад

A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-10300

почти 7 лет назад

A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS3: 8
EPSS: Низкий
ubuntu логотип

CVE-2019-10117

больше 6 лет назад

An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-10117

больше 6 лет назад

An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-10117

больше 6 лет назад

An Open Redirect issue was discovered in GitLab Community and Enterpri ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-10116

больше 6 лет назад

An Insecure Permissions issue (issue 3 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Guests of a project were allowed to see Related Branches created for an issue.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-11546

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge.

CVSS3: 5.3
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11546

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.3
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-11545

An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11545

An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11545

An issue was discovered in GitLab Community Edition 11.9.x before 11.9 ...

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-11544

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It allows Information Disclosure. Non-member users who subscribe to notifications of an internal project with issue and repository restrictions will receive emails about restricted events.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11544

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It allows Information Disclosure. Non-member users who subscribe to notifications of an internal project with issue and repository restrictions will receive emails about restricted events.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11544

An issue was discovered in GitLab Community and Enterprise Edition 8.x ...

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-11000

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11000

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11000

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 1 ...

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-10640

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input validation issue for the .gitlab-ci.yml refs value allows Uncontrolled Resource Consumption.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-10640

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input validation issue for the .gitlab-ci.yml refs value allows Uncontrolled Resource Consumption.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-10640

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-10301

A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS3: 8.8
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-10300

A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS3: 8
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-10117

An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node.

CVSS3: 6.1
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-10117

An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node.

CVSS3: 6.1
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-10117

An Open Redirect issue was discovered in GitLab Community and Enterpri ...

CVSS3: 6.1
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-10116

An Insecure Permissions issue (issue 3 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Guests of a project were allowed to see Related Branches created for an issue.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу