Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

ubuntu логотип

CVE-2017-0918

почти 8 лет назад

Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2017-0918

почти 8 лет назад

Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2017-0918

почти 8 лет назад

Gitlab Community Edition version 10.3 is vulnerable to a path traversa ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-0917

почти 8 лет назад

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-0917

почти 8 лет назад

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-0917

почти 8 лет назад

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-0916

почти 8 лет назад

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-0916

почти 8 лет назад

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-0916

почти 8 лет назад

Gitlab Community Edition version 10.3 is vulnerable to a lack of input ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-0915

почти 8 лет назад

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-0915

почти 8 лет назад

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-0915

почти 8 лет назад

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of inp ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-0914

почти 8 лет назад

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-0914

почти 8 лет назад

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-0914

почти 8 лет назад

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2. ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-0882

почти 9 лет назад

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2017-0882

почти 9 лет назад

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2017-0882

почти 9 лет назад

Multiple versions of GitLab expose sensitive user credentials when ass ...

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2016-9469

почти 9 лет назад

Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be exploited by an unauthenticated user. A fix was included in versions 8.14.3, 8.13.8, and 8.12.11, which were released on December 5th 2016 at 3:59 PST. The GitLab versions vulnerable to this are 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1, 8.14.2, and 8.14.2-ee.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2016-9469

почти 9 лет назад

Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be exploited by an unauthenticated user. A fix was included in versions 8.14.3, 8.13.8, and 8.12.11, which were released on December 5th 2016 at 3:59 PST. The GitLab versions vulnerable to this are 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1, 8.14.2, and 8.14.2-ee.

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-0918

Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution.

CVSS3: 8.8
6%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-0918

Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution.

CVSS3: 8.8
6%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-0918

Gitlab Community Edition version 10.3 is vulnerable to a path traversa ...

CVSS3: 8.8
6%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2017-0917

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.

CVSS3: 6.1
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-0917

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.

CVSS3: 6.1
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-0917

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input ...

CVSS3: 6.1
0%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2017-0916

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

CVSS3: 9.8
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-0916

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

CVSS3: 9.8
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-0916

Gitlab Community Edition version 10.3 is vulnerable to a lack of input ...

CVSS3: 9.8
0%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2017-0915

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVSS3: 9.8
1%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-0915

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVSS3: 9.8
1%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-0915

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of inp ...

CVSS3: 9.8
1%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2017-0914

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.

CVSS3: 7.5
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-0914

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.

CVSS3: 7.5
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-0914

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2. ...

CVSS3: 7.5
0%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2017-0882

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

CVSS3: 6.3
0%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-0882

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

CVSS3: 6.3
0%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-0882

Multiple versions of GitLab expose sensitive user credentials when ass ...

CVSS3: 6.3
0%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2016-9469

Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be exploited by an unauthenticated user. A fix was included in versions 8.14.3, 8.13.8, and 8.12.11, which were released on December 5th 2016 at 3:59 PST. The GitLab versions vulnerable to this are 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1, 8.14.2, and 8.14.2-ee.

CVSS3: 8.2
0%
Низкий
почти 9 лет назад
nvd логотип
CVE-2016-9469

Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be exploited by an unauthenticated user. A fix was included in versions 8.14.3, 8.13.8, and 8.12.11, which were released on December 5th 2016 at 3:59 PST. The GitLab versions vulnerable to this are 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1, 8.14.2, and 8.14.2-ee.

CVSS3: 8.2
0%
Низкий
почти 9 лет назад

Уязвимостей на страницу