Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

debian логотип

CVE-2018-17452

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2018-17451

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-17451

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-17451

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2018-17450

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2018-17450

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2018-17450

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2018-17449

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure direct object reference.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-17449

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure direct object reference.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-17449

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2018-16051

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Orphaned Upload Files Exposure.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-16051

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Orphaned Upload Files Exposure.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-16051

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2018-16050

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-16050

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-16050

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-16049

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2018-16049

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-16049

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2018-16048

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Missing Authorization Control for API Repository Storage.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2018-17452

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 9.8
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2018-17451

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2018-17451

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
debian логотип
CVE-2018-17451

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 8.8
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2018-17450

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2018-17450

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
debian логотип
CVE-2018-17450

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 4.3
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2018-17449

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure direct object reference.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2018-17449

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure direct object reference.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
debian логотип
CVE-2018-17449

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2018-16051

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Orphaned Upload Files Exposure.

CVSS3: 6.5
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-16051

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Orphaned Upload Files Exposure.

CVSS3: 6.5
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-16051

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.5
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-16050

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View.

CVSS3: 6.1
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-16050

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View.

CVSS3: 6.1
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-16050

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 6.1
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-16049

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.

CVSS3: 9.8
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-16049

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.

CVSS3: 9.8
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-16049

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 9.8
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-16048

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Missing Authorization Control for API Repository Storage.

CVSS3: 6.5
0%
Низкий
больше 7 лет назад

Уязвимостей на страницу