Количество 5 918
Количество 5 918
GHSA-m25p-vj7m-w42v
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where the assignee(s) of a confidential issue in a private project would be disclosed to a guest via milestones.
GHSA-m24j-g9jw-ggjj
GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control.
GHSA-jxx7-c7v6-wh2p
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces by manipulating namespace identifiers in API requests.
GHSA-jx85-pcwq-c9wc
An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 12.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted.
GHSA-jwfx-6cm3-63qg
An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control.
GHSA-jvc7-79q4-7754
In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.
GHSA-jrrv-jm33-8jrv
Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data
GHSA-jrjm-wgrh-4c93
An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration.. It has Insecure Permissions (issue 1 of 4).
GHSA-jr4h-pv5f-qr33
An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.
GHSA-jqw6-r3pp-rfvr
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API credentials under certain conditions.
GHSA-jqqw-x8w5-v4hh
An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.
GHSA-jqf5-5c3v-wj97
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project.
GHSA-jpgp-p76h-hmp8
An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored XSS by in the error tracking feature.
GHSA-jp4w-5rwv-5wmh
An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible to trigger a resource depletion attack due to improper filtering for number of requests to read commits details.
GHSA-jmw9-579m-cw2x
OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow
GHSA-jmj3-p7rq-pq5q
An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. This vulnerability allows for bypassing the 'group ip restriction' settings to access environment details of projects
GHSA-jm36-4mv9-x2pw
An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.
GHSA-jjj8-598g-q254
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.7.7 and 11.8.x before 11.8.3. It allows Information Disclosure.
GHSA-jj7w-rgj3-p8jw
An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive authentication information.
GHSA-jhg6-6fpm-5p2r
A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-m25p-vj7m-w42v An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where the assignee(s) of a confidential issue in a private project would be disclosed to a guest via milestones. | 1% Низкий | около 4 лет назад | ||
GHSA-m24j-g9jw-ggjj GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control. | 1% Низкий | около 4 лет назад | ||
GHSA-jxx7-c7v6-wh2p GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces by manipulating namespace identifiers in API requests. | CVSS3: 7.1 | 0% Низкий | 7 месяцев назад | |
GHSA-jx85-pcwq-c9wc An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 12.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted. | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-jwfx-6cm3-63qg An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control. | 1% Низкий | около 4 лет назад | ||
GHSA-jvc7-79q4-7754 In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export. | 1% Низкий | около 4 лет назад | ||
GHSA-jrrv-jm33-8jrv Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-jrjm-wgrh-4c93 An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration.. It has Insecure Permissions (issue 1 of 4). | 1% Низкий | около 4 лет назад | ||
GHSA-jr4h-pv5f-qr33 An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks. | 1% Низкий | около 4 лет назад | ||
GHSA-jqw6-r3pp-rfvr GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API credentials under certain conditions. | CVSS3: 2.2 | 0% Низкий | 5 месяцев назад | |
GHSA-jqqw-x8w5-v4hh An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query. | CVSS3: 2.7 | 0% Низкий | около 1 года назад | |
GHSA-jqf5-5c3v-wj97 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project. | 1% Низкий | около 4 лет назад | ||
GHSA-jpgp-p76h-hmp8 An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored XSS by in the error tracking feature. | 1% Низкий | около 4 лет назад | ||
GHSA-jp4w-5rwv-5wmh An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible to trigger a resource depletion attack due to improper filtering for number of requests to read commits details. | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
GHSA-jmw9-579m-cw2x OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow | 1% Низкий | около 4 лет назад | ||
GHSA-jmj3-p7rq-pq5q An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. This vulnerability allows for bypassing the 'group ip restriction' settings to access environment details of projects | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-jm36-4mv9-x2pw An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-jjj8-598g-q254 An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.7.7 and 11.8.x before 11.8.3. It allows Information Disclosure. | 1% Низкий | около 4 лет назад | ||
GHSA-jj7w-rgj3-p8jw An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive authentication information. | CVSS3: 4.4 | 1% Низкий | больше 1 года назад | |
GHSA-jhg6-6fpm-5p2r A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу