Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

nvd логотип

CVE-2019-10300

почти 7 лет назад

A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS3: 8
EPSS: Низкий
ubuntu логотип

CVE-2019-10117

почти 7 лет назад

An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-10117

почти 7 лет назад

An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-10117

почти 7 лет назад

An Open Redirect issue was discovered in GitLab Community and Enterpri ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-10116

почти 7 лет назад

An Insecure Permissions issue (issue 3 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Guests of a project were allowed to see Related Branches created for an issue.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-10116

почти 7 лет назад

An Insecure Permissions issue (issue 3 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Guests of a project were allowed to see Related Branches created for an issue.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-10116

почти 7 лет назад

An Insecure Permissions issue (issue 3 of 3) was discovered in GitLab ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-10115

почти 7 лет назад

An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The GitLab Releases feature could allow guest users access to private information like release details and code information.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-10115

почти 7 лет назад

An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The GitLab Releases feature could allow guest users access to private information like release details and code information.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-10115

почти 7 лет назад

An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-10114

почти 7 лет назад

An Information Exposure issue (issue 2 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. During the OAuth authentication process, the application attempts to validate a parameter in an insecure way, potentially exposing data.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-10114

почти 7 лет назад

An Information Exposure issue (issue 2 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. During the OAuth authentication process, the application attempts to validate a parameter in an insecure way, potentially exposing data.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-10114

почти 7 лет назад

An Information Exposure issue (issue 2 of 2) was discovered in GitLab ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-10113

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Making concurrent GET /api/v4/projects/<id>/languages requests may allow Uncontrolled Resource Consumption.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-10113

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Making concurrent GET /api/v4/projects/<id>/languages requests may allow Uncontrolled Resource Consumption.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-10113

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-10112

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The construction of the HMAC key was insecurely derived.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-10112

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The construction of the HMAC key was insecurely derived.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-10112

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-10111

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allows persistent XSS in the merge request "resolve conflicts" page.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-10300

A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS3: 8
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-10117

An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node.

CVSS3: 6.1
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-10117

An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node.

CVSS3: 6.1
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-10117

An Open Redirect issue was discovered in GitLab Community and Enterpri ...

CVSS3: 6.1
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-10116

An Insecure Permissions issue (issue 3 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Guests of a project were allowed to see Related Branches created for an issue.

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-10116

An Insecure Permissions issue (issue 3 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Guests of a project were allowed to see Related Branches created for an issue.

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-10116

An Insecure Permissions issue (issue 3 of 3) was discovered in GitLab ...

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-10115

An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The GitLab Releases feature could allow guest users access to private information like release details and code information.

CVSS3: 6.5
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-10115

An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The GitLab Releases feature could allow guest users access to private information like release details and code information.

CVSS3: 6.5
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-10115

An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab ...

CVSS3: 6.5
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-10114

An Information Exposure issue (issue 2 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. During the OAuth authentication process, the application attempts to validate a parameter in an insecure way, potentially exposing data.

CVSS3: 7.5
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-10114

An Information Exposure issue (issue 2 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. During the OAuth authentication process, the application attempts to validate a parameter in an insecure way, potentially exposing data.

CVSS3: 7.5
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-10114

An Information Exposure issue (issue 2 of 2) was discovered in GitLab ...

CVSS3: 7.5
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-10113

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Making concurrent GET /api/v4/projects/<id>/languages requests may allow Uncontrolled Resource Consumption.

CVSS3: 7.5
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-10113

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Making concurrent GET /api/v4/projects/<id>/languages requests may allow Uncontrolled Resource Consumption.

CVSS3: 7.5
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-10113

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-10112

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The construction of the HMAC key was insecurely derived.

CVSS3: 7.5
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-10112

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The construction of the HMAC key was insecurely derived.

CVSS3: 7.5
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-10112

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-10111

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allows persistent XSS in the merge request "resolve conflicts" page.

CVSS3: 5.4
0%
Низкий
почти 7 лет назад

Уязвимостей на страницу