Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 943

Количество 5 943

nvd логотип

CVE-2019-12825

больше 6 лет назад

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-12825

больше 6 лет назад

Unauthorized Access to the Container Registry of other groups was disc ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-12446

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-12446

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-12446

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.3 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-12445

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-12445

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2019-12445

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.4 ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2019-12444

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-12444

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-12444

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.9 ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-12443

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-12443

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-12443

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2019-12442

больше 6 лет назад

An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-12442

больше 6 лет назад

An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-12442

больше 6 лет назад

An issue was discovered in GitLab Enterprise Edition 11.7 through 11.1 ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-12441

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-12441

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-12441

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.4 ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-12825

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

CVSS3: 4.3
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12825

Unauthorized Access to the Container Registry of other groups was disc ...

CVSS3: 4.3
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-12446

An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.

CVSS3: 7.5
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-12446

An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.

CVSS3: 7.5
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12446

An issue was discovered in GitLab Community and Enterprise Edition 8.3 ...

CVSS3: 7.5
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-12445

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.

CVSS3: 5.4
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-12445

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.

CVSS3: 5.4
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12445

An issue was discovered in GitLab Community and Enterprise Edition 8.4 ...

CVSS3: 5.4
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-12444

An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-12444

An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12444

An issue was discovered in GitLab Community and Enterprise Edition 8.9 ...

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-12443

An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks.

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-12443

An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks.

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12443

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-12442

An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-12442

An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12442

An issue was discovered in GitLab Enterprise Edition 11.7 through 11.1 ...

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-12441

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.

CVSS3: 7.5
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-12441

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.

CVSS3: 7.5
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12441

An issue was discovered in GitLab Community and Enterprise Edition 8.4 ...

CVSS3: 7.5
1%
Низкий
больше 6 лет назад

Уязвимостей на страницу