Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

nvd логотип

CVE-2018-19572

больше 6 лет назад

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2018-19572

больше 6 лет назад

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-c ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2018-19571

больше 6 лет назад

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

CVSS3: 7.7
EPSS: Средний
nvd логотип

CVE-2018-19571

больше 6 лет назад

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

CVSS3: 7.7
EPSS: Средний
debian логотип

CVE-2018-19571

больше 6 лет назад

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11. ...

CVSS3: 7.7
EPSS: Средний
ubuntu логотип

CVE-2018-19570

больше 6 лет назад

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-19570

больше 6 лет назад

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-19570

больше 6 лет назад

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11 ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2018-19569

больше 6 лет назад

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-19569

больше 6 лет назад

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-19569

больше 6 лет назад

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4 ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2018-19496

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-19496

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-19496

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2018-19495

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-19495

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-19495

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2018-19494

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2018-19494

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2018-19494

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-19572

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

CVSS3: 5.9
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-19572

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-c ...

CVSS3: 5.9
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-19571

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

CVSS3: 7.7
35%
Средний
больше 6 лет назад
nvd логотип
CVE-2018-19571

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

CVSS3: 7.7
35%
Средний
больше 6 лет назад
debian логотип
CVE-2018-19571

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11. ...

CVSS3: 7.7
35%
Средний
больше 6 лет назад
ubuntu логотип
CVE-2018-19570

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-19570

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-19570

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11 ...

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-19569

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-19569

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-19569

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4 ...

CVSS3: 8.8
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-19496

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-19496

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-19496

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-19495

An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration.

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-19495

An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration.

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-19495

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-19494

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-19494

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-19494

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 4.3
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу