Количество 5 336
Количество 5 336
CVE-2016-9469
Multiple versions of GitLab expose a dangerous method to any authentic ...
CVE-2016-9086
GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files (tar). All GitLab versions prior to 8.13.0 restricted this feature to administrators only. Starting with version 8.13.0 this feature was made available to all users. This feature did not properly check for symbolic links in user-provided archives and therefore it was possible for an authenticated user to retrieve the contents of any file accessible to the GitLab service account. This included sensitive files such as those that contain secret tokens used by the GitLab service to authenticate users. GitLab CE and EE versions 8.13.0 through 8.13.2, 8.12.0 through 8.12.7, 8.11.0 through 8.11.10, 8.10.0 through 8.10.12, and 8.9.0 through 8.9.11 are affected.
CVE-2016-9086
GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files (tar). All GitLab versions prior to 8.13.0 restricted this feature to administrators only. Starting with version 8.13.0 this feature was made available to all users. This feature did not properly check for symbolic links in user-provided archives and therefore it was possible for an authenticated user to retrieve the contents of any file accessible to the GitLab service account. This included sensitive files such as those that contain secret tokens used by the GitLab service to authenticate users. GitLab CE and EE versions 8.13.0 through 8.13.2, 8.12.0 through 8.12.7, 8.11.0 through 8.11.10, 8.10.0 through 8.10.12, and 8.9.0 through 8.9.11 are affected.
CVE-2016-9086
GitLab versions 8.9.x and above contain a critical security flaw in th ...
CVE-2016-4340
The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.
CVE-2016-4340
The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.
CVE-2016-4340
The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 th ...
CVE-2014-8540
The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.
CVE-2014-8540
The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authen ...
CVE-2014-3456
Cross-site scripting (XSS) vulnerability in GitLab Enterprise Edition (EE) 6.6.0 before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-7316
Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML file, as demonstrated by README.html.
CVE-2013-7316
Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versi ...
CVE-2013-4580
GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.
CVE-2013-4580
GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Ed ...
CVE-2013-4489
The Grit gem for Ruby, as used in GitLab 5.2 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands, as demonstrated by the search box for the GitLab code search feature.
CVE-2013-4489
The Grit gem for Ruby, as used in GitLab 5.2 before 5.4.1 and 6.x befo ...
BDU:2026-00990
Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с исчерпанием ресурсов памяти, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2026-00989
Уязвимость конфигурации программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю раскрыть защищаемую информацию из отчетов по безопасности
BDU:2026-00982
Уязвимость программной платформы на базе git для совместной работы над кодом GitLab CE/EE, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании путем настройки неверных вики-документов
BDU:2026-00979
Уязвимость программной платформы на базе git для совместной работы над кодом GitLab CE/EE, связанная с недостатками процедуры авторизации, позволяющая нарушителю вызвать отказ в обслуживании
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2016-9469 Multiple versions of GitLab expose a dangerous method to any authentic ... | CVSS3: 8.2 | 0% Низкий | почти 9 лет назад | |
CVE-2016-9086 GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files (tar). All GitLab versions prior to 8.13.0 restricted this feature to administrators only. Starting with version 8.13.0 this feature was made available to all users. This feature did not properly check for symbolic links in user-provided archives and therefore it was possible for an authenticated user to retrieve the contents of any file accessible to the GitLab service account. This included sensitive files such as those that contain secret tokens used by the GitLab service to authenticate users. GitLab CE and EE versions 8.13.0 through 8.13.2, 8.12.0 through 8.12.7, 8.11.0 through 8.11.10, 8.10.0 through 8.10.12, and 8.9.0 through 8.9.11 are affected. | CVSS3: 6.5 | 13% Средний | больше 9 лет назад | |
CVE-2016-9086 GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files (tar). All GitLab versions prior to 8.13.0 restricted this feature to administrators only. Starting with version 8.13.0 this feature was made available to all users. This feature did not properly check for symbolic links in user-provided archives and therefore it was possible for an authenticated user to retrieve the contents of any file accessible to the GitLab service account. This included sensitive files such as those that contain secret tokens used by the GitLab service to authenticate users. GitLab CE and EE versions 8.13.0 through 8.13.2, 8.12.0 through 8.12.7, 8.11.0 through 8.11.10, 8.10.0 through 8.10.12, and 8.9.0 through 8.9.11 are affected. | CVSS3: 6.5 | 13% Средний | больше 9 лет назад | |
CVE-2016-9086 GitLab versions 8.9.x and above contain a critical security flaw in th ... | CVSS3: 6.5 | 13% Средний | больше 9 лет назад | |
CVE-2016-4340 The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors. | CVSS3: 8.8 | 2% Низкий | около 9 лет назад | |
CVE-2016-4340 The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors. | CVSS3: 8.8 | 2% Низкий | около 9 лет назад | |
CVE-2016-4340 The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 th ... | CVSS3: 8.8 | 2% Низкий | около 9 лет назад | |
CVE-2014-8540 The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks. | CVSS3: 6.5 | 0% Низкий | около 8 лет назад | |
CVE-2014-8540 The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authen ... | CVSS3: 6.5 | 0% Низкий | около 8 лет назад | |
CVE-2014-3456 Cross-site scripting (XSS) vulnerability in GitLab Enterprise Edition (EE) 6.6.0 before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | CVSS2: 4.3 | 0% Низкий | больше 11 лет назад | |
CVE-2013-7316 Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML file, as demonstrated by README.html. | CVSS2: 4.3 | 1% Низкий | около 12 лет назад | |
CVE-2013-7316 Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versi ... | CVSS2: 4.3 | 1% Низкий | около 12 лет назад | |
CVE-2013-4580 GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls. | CVSS2: 6.8 | 0% Низкий | больше 11 лет назад | |
CVE-2013-4580 GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Ed ... | CVSS2: 6.8 | 0% Низкий | больше 11 лет назад | |
CVE-2013-4489 The Grit gem for Ruby, as used in GitLab 5.2 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands, as demonstrated by the search box for the GitLab code search feature. | CVSS2: 6.5 | 0% Низкий | больше 11 лет назад | |
CVE-2013-4489 The Grit gem for Ruby, as used in GitLab 5.2 before 5.4.1 and 6.x befo ... | CVSS2: 6.5 | 0% Низкий | больше 11 лет назад | |
BDU:2026-00990 Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с исчерпанием ресурсов памяти, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
BDU:2026-00989 Уязвимость конфигурации программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю раскрыть защищаемую информацию из отчетов по безопасности | CVSS3: 4.3 | 0% Низкий | 2 месяца назад | |
BDU:2026-00982 Уязвимость программной платформы на базе git для совместной работы над кодом GitLab CE/EE, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании путем настройки неверных вики-документов | CVSS3: 6.5 | 0% Низкий | 17 дней назад | |
BDU:2026-00979 Уязвимость программной платформы на базе git для совместной работы над кодом GitLab CE/EE, связанная с недостатками процедуры авторизации, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | 17 дней назад |
Уязвимостей на страницу