Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 918

Количество 5 918

github логотип

GHSA-j94v-jxmv-27r2

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external provider configuration. As a result, the user may not be marked as external thereby giving those users access to internal projects or groups.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-j8qf-xxg6-jf5p

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-j8p4-7v92-r64p

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability.

EPSS: Низкий
github логотип

GHSA-j8mj-5fpw-2pc8

больше 2 лет назад

An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-j8j9-23cp-fr5v

8 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a Denial of Service condition by sending crafted API calls with large content parameters.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-j875-427q-5q22

около 1 года назад

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-j7c9-9cr2-9pq2

3 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to bypass merge request approval requirements due to improper cleanup of orphaned policy records.

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-j76w-jg9r-w5vr

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server. Affected versions are: >=8.14, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-j73p-8vp4-6g28

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A small number of GitLab API endpoints would disclose project information when using a read_user scoped token.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-j733-4p4j-wcmp

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Non-project members could retrieve release descriptions via the API, even if the release visibility is restricted to project members only in the project settings.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-j6mw-w229-ppqm

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. blog-viewer has stored XSS during repository browsing, if package.json exists. .

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-j6mm-pjh3-2fh5

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 prior to 17.5.5, from 17.6 prior to 17.6.3, and from 17.7 prior to 17.7.1. Under certain conditions, processing of CI artifacts metadata could cause background jobs to become unresponsive.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-j6h5-jcwm-38vr

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

EPSS: Средний
github логотип

GHSA-j5xm-2wp4-36g2

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prior to 17.2.4, and starting from 17.3 prior to 17.3.1, which allows an attacker to create a branch with the same name as a deleted tag.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-j592-x6jp-9fg8

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to make unintended internal requests through proxy environments under certain conditions due to improper input validation in import functionality.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-j56p-cx78-v9ch

10 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-j48w-jfc5-3885

больше 3 лет назад

An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they don't have access to.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-j45p-g8pv-jg87

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-j42x-rxgc-89xm

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to make unintended internal requests through proxy environments by injecting crafted sequences.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-j42v-fg25-q7fp

около 4 лет назад

A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-j94v-jxmv-27r2

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external provider configuration. As a result, the user may not be marked as external thereby giving those users access to internal projects or groups.

CVSS3: 4.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-j8qf-xxg6-jf5p

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-j8p4-7v92-r64p

An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability.

1%
Низкий
около 4 лет назад
github логотип
GHSA-j8mj-5fpw-2pc8

An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-j8j9-23cp-fr5v

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a Denial of Service condition by sending crafted API calls with large content parameters.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-j875-427q-5q22

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 8.7
1%
Низкий
около 1 года назад
github логотип
GHSA-j7c9-9cr2-9pq2

GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to bypass merge request approval requirements due to improper cleanup of orphaned policy records.

CVSS3: 2.6
0%
Низкий
3 месяца назад
github логотип
GHSA-j76w-jg9r-w5vr

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server. Affected versions are: >=8.14, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

2%
Низкий
около 4 лет назад
github логотип
GHSA-j73p-8vp4-6g28

An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A small number of GitLab API endpoints would disclose project information when using a read_user scoped token.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-j733-4p4j-wcmp

An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Non-project members could retrieve release descriptions via the API, even if the release visibility is restricted to project members only in the project settings.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-j6mw-w229-ppqm

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. blog-viewer has stored XSS during repository browsing, if package.json exists. .

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-j6mm-pjh3-2fh5

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 prior to 17.5.5, from 17.6 prior to 17.6.3, and from 17.7 prior to 17.7.1. Under certain conditions, processing of CI artifacts metadata could cause background jobs to become unresponsive.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-j6h5-jcwm-38vr

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

35%
Средний
около 4 лет назад
github логотип
GHSA-j5xm-2wp4-36g2

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prior to 17.2.4, and starting from 17.3 prior to 17.3.1, which allows an attacker to create a branch with the same name as a deleted tag.

CVSS3: 5.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-j592-x6jp-9fg8

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to make unintended internal requests through proxy environments under certain conditions due to improper input validation in import functionality.

CVSS3: 5
0%
Низкий
5 месяцев назад
github логотип
GHSA-j56p-cx78-v9ch

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-j48w-jfc5-3885

An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they don't have access to.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-j45p-g8pv-jg87

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-j42x-rxgc-89xm

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to make unintended internal requests through proxy environments by injecting crafted sequences.

CVSS3: 8.5
1%
Низкий
11 месяцев назад
github логотип
GHSA-j42v-fg25-q7fp

A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile

1%
Низкий
около 4 лет назад

Уязвимостей на страницу