Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 332

Количество 5 332

github логотип

GHSA-h99g-4c6w-94rj

больше 3 лет назад

In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands.

EPSS: Низкий
github логотип

GHSA-h98w-jf8x-jw68

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to create model experiments in public projects.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-h963-mpc3-j9g4

больше 3 лет назад

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

EPSS: Низкий
github логотип

GHSA-h93x-rrp4-r26c

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.9 and later through 12.0.2. GitLab Snippets were vulnerable to an authorization issue that allowed unauthorized users to add comments to a private snippet. It allows authentication bypass.

EPSS: Низкий
github логотип

GHSA-h93h-vj2c-pxf9

больше 3 лет назад

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

EPSS: Низкий
github логотип

GHSA-h8h7-r99g-m28c

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-h7pc-v4hv-wjwm

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. Its User Interface has a Misrepresentation of Critical Information.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-h79h-c7qx-243v

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-h782-mprg-p5xv

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible to trigger a DoS attack by uploading a malicious nuget package.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-h743-v64g-4f2g

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab reveals if a user has enabled two-factor authentication on their account in the HTML source, to unauthenticated users.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-h6w2-q947-gwv4

больше 3 лет назад

A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1

EPSS: Низкий
github логотип

GHSA-h6qj-3xrq-vxh8

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-h62c-3g8w-9vjr

8 месяцев назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. Arbitrary access to the titles of an private specific references could be leaked through the service-desk custom email template.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-h5fq-66m8-wp4v

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 1 of 5).

EPSS: Низкий
github логотип

GHSA-h4mq-8rq4-7m7x

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-h453-7rrx-q6j5

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-h43r-6wwr-vj3g

больше 3 лет назад

GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the issue was made Confidential.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-h42v-738f-q57f

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.

EPSS: Низкий
github логотип

GHSA-h3v8-2pff-ph95

больше 3 лет назад

GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-h3r9-rg3q-7f5f

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to edit labels description by an unauthorised user.

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-h99g-4c6w-94rj

In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h98w-jf8x-jw68

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to create model experiments in public projects.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-h963-mpc3-j9g4

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h93x-rrp4-r26c

An issue was discovered in GitLab Community and Enterprise Edition 11.9 and later through 12.0.2. GitLab Snippets were vulnerable to an authorization issue that allowed unauthorized users to add comments to a private snippet. It allows authentication bypass.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h93h-vj2c-pxf9

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h8h7-r99g-m28c

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.

CVSS3: 4.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-h7pc-v4hv-wjwm

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. Its User Interface has a Misrepresentation of Critical Information.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-h79h-c7qx-243v

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-h782-mprg-p5xv

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible to trigger a DoS attack by uploading a malicious nuget package.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-h743-v64g-4f2g

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab reveals if a user has enabled two-factor authentication on their account in the HTML source, to unauthenticated users.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-h6w2-q947-gwv4

A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h6qj-3xrq-vxh8

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.

CVSS3: 8.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-h62c-3g8w-9vjr

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. Arbitrary access to the titles of an private specific references could be leaked through the service-desk custom email template.

CVSS3: 3.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-h5fq-66m8-wp4v

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 1 of 5).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h4mq-8rq4-7m7x

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-h453-7rrx-q6j5

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-h43r-6wwr-vj3g

GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the issue was made Confidential.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-h42v-738f-q57f

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h3v8-2pff-ph95

GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-h3r9-rg3q-7f5f

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to edit labels description by an unauthorised user.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу