Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 203

Количество 5 203

github логотип

GHSA-xcgm-v273-44cr

около 2 лет назад

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-x3fv-8jf3-r4h2

больше 3 лет назад

The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.

EPSS: Низкий
github логотип

GHSA-wpgv-98gg-67q7

больше 3 лет назад

The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to include information from local files into the metadata of a Git repository via the web interface.

EPSS: Низкий
github логотип

GHSA-v9h3-mqgc-w575

больше 3 лет назад

GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.

EPSS: Низкий
github логотип

GHSA-r692-jg36-6v4p

больше 3 лет назад

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.

EPSS: Низкий
github логотип

GHSA-jwcg-x754-2vpg

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-hj56-84jw-67h6

больше 4 лет назад

Potential Denial-of-Service in bindata

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-9hhr-gwc7-jcvh

больше 3 лет назад

The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.

EPSS: Средний
ubuntu логотип

CVE-2023-5332

около 2 лет назад

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2023-5332

около 2 лет назад

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2023-5332

около 2 лет назад

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2023-5332

около 2 лет назад

Patch in third party library Consul requires 'enable-script-checks' to ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2022-3573

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-3573

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-3573

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2021-32823

больше 4 лет назад

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2021-32823

больше 4 лет назад

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2021-32823

больше 4 лет назад

In the bindata RubyGem before version 2.4.10 there is a potential deni ...

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2013-4583

почти 6 лет назад

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2013-4583

почти 6 лет назад

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4 ...

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xcgm-v273-44cr

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-x3fv-8jf3-r4h2

The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wpgv-98gg-67q7

The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to include information from local files into the metadata of a Git repository via the web interface.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-v9h3-mqgc-w575

GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-r692-jg36-6v4p

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-jwcg-x754-2vpg

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-hj56-84jw-67h6

Potential Denial-of-Service in bindata

CVSS3: 3.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-9hhr-gwc7-jcvh

The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.

48%
Средний
больше 3 лет назад
ubuntu логотип
CVE-2023-5332

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
0%
Низкий
около 2 лет назад
redhat логотип
CVE-2023-5332

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 8.1
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-5332

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-5332

Patch in third party library Consul requires 'enable-script-checks' to ...

CVSS3: 5.9
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2022-3573

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-3573

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
1%
Низкий
почти 3 года назад
debian логотип
CVE-2022-3573

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.4
1%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2021-32823

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.

CVSS3: 3.7
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-32823

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.

CVSS3: 3.7
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-32823

In the bindata RubyGem before version 2.4.10 there is a potential deni ...

CVSS3: 3.7
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2013-4583

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.

CVSS3: 8.8
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2013-4583

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4 ...

CVSS3: 8.8
0%
Низкий
почти 6 лет назад

Уязвимостей на страницу