Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 918

Количество 5 918

github логотип

GHSA-jh26-hqr4-2cjg

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-jgpj-vfxg-97h5

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-jgp3-92wq-g4pq

9 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to trigger unauthorized pipeline executions by manipulating commits.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-jg83-cqm8-3pp5

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-jg7j-6r85-5w9p

около 4 лет назад

GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.

EPSS: Низкий
github логотип

GHSA-jg7h-cr7w-5fc6

около 4 лет назад

An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-jg4r-vvqm-988m

около 4 лет назад

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-jfx9-cc6f-6x6q

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to cause denial of service due to uncontrolled resource consumption when processing a specially crafted file upload.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-jfvv-q6f6-m4g5

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to inject HTML and JavaScript into email notifications sent to other users due to improper input sanitization.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-jfvp-pw77-78h3

3 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by uploading a specially crafted file due to improper validation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-jcwq-43pm-wp74

около 4 лет назад

Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.

EPSS: Низкий
github логотип

GHSA-jcrh-hfqv-cr47

около 4 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abused to perform denial of service attacks due to the lack of rate limitation.

EPSS: Низкий
github логотип

GHSA-jc72-5mcm-wv54

около 4 лет назад

GitLab through 12.9 is affected by a potential DoS in repository archive download.

EPSS: Низкий
github логотип

GHSA-jc6j-h8ph-rhgw

около 4 лет назад

GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure.

EPSS: Низкий
github логотип

GHSA-jc6h-6j87-fx8m

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-jc5r-hf66-vmm4

больше 3 лет назад

A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-jc5p-hfq2-7mfm

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-jc2r-hgpx-4q9p

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to bypass package protection rules due to improper access control.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-j9w8-4m8f-75m4

8 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 13.2 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to disclose sensitive information from private projects by executing specifically crafted GraphQL queries.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-j9jv-5q76-4q2h

5 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an authenticated user to cause denial of service by exploiting a Bitbucket Server import endpoint via repeatedly sending large responses.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-jh26-hqr4-2cjg

An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-jgpj-vfxg-97h5

An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.

CVSS3: 4.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-jgp3-92wq-g4pq

GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to trigger unauthorized pipeline executions by manipulating commits.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-jg83-cqm8-3pp5

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-jg7j-6r85-5w9p

GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.

1%
Низкий
около 4 лет назад
github логотип
GHSA-jg7h-cr7w-5fc6

An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-jg4r-vvqm-988m

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

1%
Низкий
около 4 лет назад
github логотип
GHSA-jfx9-cc6f-6x6q

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to cause denial of service due to uncontrolled resource consumption when processing a specially crafted file upload.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-jfvv-q6f6-m4g5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to inject HTML and JavaScript into email notifications sent to other users due to improper input sanitization.

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-jfvp-pw77-78h3

GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by uploading a specially crafted file due to improper validation.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-jcwq-43pm-wp74

Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.

1%
Низкий
около 4 лет назад
github логотип
GHSA-jcrh-hfqv-cr47

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abused to perform denial of service attacks due to the lack of rate limitation.

2%
Низкий
около 4 лет назад
github логотип
GHSA-jc72-5mcm-wv54

GitLab through 12.9 is affected by a potential DoS in repository archive download.

1%
Низкий
около 4 лет назад
github логотип
GHSA-jc6j-h8ph-rhgw

GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure.

1%
Низкий
около 4 лет назад
github логотип
GHSA-jc6h-6j87-fx8m

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-jc5r-hf66-vmm4

A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-jc5p-hfq2-7mfm

An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-jc2r-hgpx-4q9p

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to bypass package protection rules due to improper access control.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-j9w8-4m8f-75m4

GitLab has remediated an issue in GitLab EE affecting all versions from 13.2 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to disclose sensitive information from private projects by executing specifically crafted GraphQL queries.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-j9jv-5q76-4q2h

An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an authenticated user to cause denial of service by exploiting a Bitbucket Server import endpoint via repeatedly sending large responses.

CVSS3: 6.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу