Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 332

Количество 5 332

github логотип

GHSA-hv89-cw42-xpf3

7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthorized user to access custom service desk email addresses.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-hv57-5vj6-78w5

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to unmask webhook secret tokens by reviewing the logs after testing webhooks.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-hrrx-p8r8-gj4g

больше 3 лет назад

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

CVSS3: 7.7
EPSS: Средний
github логотип

GHSA-hqrv-q53h-4xwq

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. Unauthorized users were able to read pipeline information of the last merge request. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-hmrg-q92x-qw2x

около 2 лет назад

A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-hmgf-x64m-9gcw

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted request.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-hm29-m2fx-r7p5

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Denial of Service. Inputting an overly long string into a Markdown field could cause a denial of service.

EPSS: Низкий
github логотип

GHSA-hm25-53gr-mc5r

почти 4 года назад

In all versions of GitLab CE/EE, certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-hjx6-96hg-jf7x

больше 3 лет назад

An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious authenticated user to view a public project's Deploy Key's public fingerprint and name when that key has write permission. Note that GitLab never asks for nor stores the private key.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-hjrv-mr9m-rffp

больше 3 лет назад

GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the Jaeger Tracing Operations page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hjr5-q2v6-7chx

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-hhh4-9fpj-93rw

почти 4 года назад

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-hgr5-p9jr-23mm

больше 3 лет назад

Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hgm9-86j2-97g5

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 1 of 6). An authorization issue allows the contributed project information of a private profile to be viewed.

EPSS: Низкий
github логотип

GHSA-hg4v-vm5j-rq45

больше 3 лет назад

User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1

EPSS: Низкий
github логотип

GHSA-hf2f-3fp9-m472

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use AutolinkFilter to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-hcwc-2gm5-v9g6

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not restricting the amount of results one could request, potentially resulting in a denial of service.

EPSS: Низкий
github логотип

GHSA-hchv-vv89-9pxp

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted requests to a specific endpoint, even if the victim user has 2FA enabled on their account.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-h9jj-wh2c-fq64

больше 3 лет назад

An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. GitLab was vulnerable to a stored XSS by using the PyPi files API.

EPSS: Низкий
github логотип

GHSA-h9gg-fc6x-px6c

больше 3 лет назад

Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-hv89-cw42-xpf3

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthorized user to access custom service desk email addresses.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-hv57-5vj6-78w5

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to unmask webhook secret tokens by reviewing the logs after testing webhooks.

CVSS3: 6.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-hrrx-p8r8-gj4g

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

CVSS3: 7.7
35%
Средний
больше 3 лет назад
github логотип
GHSA-hqrv-q53h-4xwq

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. Unauthorized users were able to read pipeline information of the last merge request. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hmrg-q92x-qw2x

A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner

CVSS3: 4.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-hmgf-x64m-9gcw

An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted request.

CVSS3: 2.7
1%
Низкий
почти 3 года назад
github логотип
GHSA-hm29-m2fx-r7p5

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Denial of Service. Inputting an overly long string into a Markdown field could cause a denial of service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hm25-53gr-mc5r

In all versions of GitLab CE/EE, certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-hjx6-96hg-jf7x

An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious authenticated user to view a public project's Deploy Key's public fingerprint and name when that key has write permission. Note that GitLab never asks for nor stores the private key.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-hjrv-mr9m-rffp

GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the Jaeger Tracing Operations page.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-hjr5-q2v6-7chx

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-hhh4-9fpj-93rw

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-hgr5-p9jr-23mm

Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-hgm9-86j2-97g5

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 1 of 6). An authorization issue allows the contributed project information of a private profile to be viewed.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hg4v-vm5j-rq45

User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hf2f-3fp9-m472

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use AutolinkFilter to the preview_markdown endpoint.

CVSS3: 7.5
5%
Низкий
больше 2 лет назад
github логотип
GHSA-hcwc-2gm5-v9g6

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not restricting the amount of results one could request, potentially resulting in a denial of service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hchv-vv89-9pxp

An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted requests to a specific endpoint, even if the victim user has 2FA enabled on their account.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-h9jj-wh2c-fq64

An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. GitLab was vulnerable to a stored XSS by using the PyPi files API.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h9gg-fc6x-px6c

Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу