Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

ubuntu логотип

CVE-2019-10109

больше 6 лет назад

An Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. EXIF geolocation data were not removed from images when uploaded to GitLab. As a result, anyone with access to the uploaded image could obtain its geolocation, device, and software version data (if present).

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-10109

больше 6 лет назад

An Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. EXIF geolocation data were not removed from images when uploaded to GitLab. As a result, anyone with access to the uploaded image could obtain its geolocation, device, and software version data (if present).

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-10109

больше 6 лет назад

An Information Exposure issue (issue 1 of 2) was discovered in GitLab ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2019-10108

больше 6 лет назад

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-10108

больше 6 лет назад

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2019-10108

больше 6 лет назад

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Co ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2018-9244

почти 8 лет назад

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-9244

почти 8 лет назад

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-9244

почти 8 лет назад

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vu ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-9243

почти 8 лет назад

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-9243

почти 8 лет назад

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-9243

почти 8 лет назад

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vu ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-8971

почти 8 лет назад

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2018-8971

почти 8 лет назад

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-8971

почти 8 лет назад

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, a ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2018-8801

почти 8 лет назад

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-8801

почти 8 лет назад

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-8801

почти 8 лет назад

GitLab Community and Enterprise Editions version 8.3 up to 10.x before ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2018-3710

почти 8 лет назад

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2018-3710

почти 8 лет назад

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-10109

An Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. EXIF geolocation data were not removed from images when uploaded to GitLab. As a result, anyone with access to the uploaded image could obtain its geolocation, device, and software version data (if present).

CVSS3: 5.3
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-10109

An Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. EXIF geolocation data were not removed from images when uploaded to GitLab. As a result, anyone with access to the uploaded image could obtain its geolocation, device, and software version data (if present).

CVSS3: 5.3
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-10109

An Information Exposure issue (issue 1 of 2) was discovered in GitLab ...

CVSS3: 5.3
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-10108

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels.

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-10108

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels.

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-10108

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Co ...

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-9244

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-9244

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-9244

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vu ...

CVSS3: 6.1
0%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2018-9243

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-9243

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-9243

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vu ...

CVSS3: 6.1
0%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2018-8971

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS3: 9.8
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-8971

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS3: 9.8
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-8971

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, a ...

CVSS3: 9.8
0%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2018-8801

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-8801

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-8801

GitLab Community and Enterprise Editions version 8.3 up to 10.x before ...

CVSS3: 6.5
0%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2018-3710

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

CVSS3: 7.8
5%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-3710

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

CVSS3: 7.8
5%
Низкий
почти 8 лет назад

Уязвимостей на страницу