Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 918

Количество 5 918

github логотип

GHSA-j3mj-q4f3-88pf

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by sending specially crafted GraphQL requests due to uncontrolled recursion under certain circumstances.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-j3cw-xpxv-w9fr

около 4 лет назад

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-j365-62px-vjjv

около 4 лет назад

Jenkins GitLab Plugin Cross-Site Request Forgery vulnerability

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-j34f-v6r4-25vh

около 4 лет назад

Missing access control in GitLab version 13.10 and above with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-j2mx-xc3v-gw3q

почти 2 года назад

An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-j24v-67h6-cx49

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions when OpenID Connect is enabled on an instance, it may allow users who are marked as 'external' to become 'regular' users thus leading to privilege escalation for those users.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-hxvp-f87c-vpq8

около 4 лет назад

All versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11 do not send an email to the old email address when an email address change is made.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-hxc7-qjfv-5432

почти 4 года назад

A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a special crafted input added in the Commit message field.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-hwx9-j325-fw69

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

EPSS: Низкий
github логотип

GHSA-hwhg-29fx-c3jc

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-hw95-w73v-wf42

около 4 лет назад

Accidental logging of system root password in the migration log in all versions of GitLab CE/EE allows an attacker with local file system access to obtain system root-level privileges

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-hv8g-9cgr-4hmc

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to execute arbitrary GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-hv89-cw42-xpf3

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthorized user to access custom service desk email addresses.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-hv57-5vj6-78w5

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to unmask webhook secret tokens by reviewing the logs after testing webhooks.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-hrrx-p8r8-gj4g

около 4 лет назад

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

CVSS3: 7.7
EPSS: Средний
github логотип

GHSA-hqrv-q53h-4xwq

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. Unauthorized users were able to read pipeline information of the last merge request. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-hmrg-q92x-qw2x

больше 2 лет назад

A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-hmgf-x64m-9gcw

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted request.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-hm74-p2xf-rqgc

около 2 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with Security Manager-role permissions to manage project security configuration even when the relevant feature was in a disabled state, due to incorrect authorization enforcement.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-hm29-m2fx-r7p5

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Denial of Service. Inputting an overly long string into a Markdown field could cause a denial of service.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-j3mj-q4f3-88pf

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by sending specially crafted GraphQL requests due to uncontrolled recursion under certain circumstances.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-j3cw-xpxv-w9fr

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

CVSS3: 5.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-j365-62px-vjjv

Jenkins GitLab Plugin Cross-Site Request Forgery vulnerability

CVSS3: 8
1%
Низкий
около 4 лет назад
github логотип
GHSA-j34f-v6r4-25vh

Missing access control in GitLab version 13.10 and above with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-j2mx-xc3v-gw3q

An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.

CVSS3: 6.6
1%
Низкий
почти 2 года назад
github логотип
GHSA-j24v-67h6-cx49

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions when OpenID Connect is enabled on an instance, it may allow users who are marked as 'external' to become 'regular' users thus leading to privilege escalation for those users.

CVSS3: 6.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-hxvp-f87c-vpq8

All versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11 do not send an email to the old email address when an email address change is made.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-hxc7-qjfv-5432

A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a special crafted input added in the Commit message field.

CVSS3: 4.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-hwx9-j325-fw69

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

2%
Низкий
около 4 лет назад
github логотип
GHSA-hwhg-29fx-c3jc

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-hw95-w73v-wf42

Accidental logging of system root password in the migration log in all versions of GitLab CE/EE allows an attacker with local file system access to obtain system root-level privileges

CVSS3: 6.7
0%
Низкий
около 4 лет назад
github логотип
GHSA-hv8g-9cgr-4hmc

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to execute arbitrary GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.

CVSS3: 8.1
0%
Низкий
4 месяца назад
github логотип
GHSA-hv89-cw42-xpf3

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthorized user to access custom service desk email addresses.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-hv57-5vj6-78w5

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to unmask webhook secret tokens by reviewing the logs after testing webhooks.

CVSS3: 6.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-hrrx-p8r8-gj4g

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

CVSS3: 7.7
28%
Средний
около 4 лет назад
github логотип
GHSA-hqrv-q53h-4xwq

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. Unauthorized users were able to read pipeline information of the last merge request. It has Incorrect Access Control.

1%
Низкий
около 4 лет назад
github логотип
GHSA-hmrg-q92x-qw2x

A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner

CVSS3: 4.9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-hmgf-x64m-9gcw

An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted request.

CVSS3: 2.7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-hm74-p2xf-rqgc

GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with Security Manager-role permissions to manage project security configuration even when the relevant feature was in a disabled state, due to incorrect authorization enforcement.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-hm29-m2fx-r7p5

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Denial of Service. Inputting an overly long string into a Markdown field could cause a denial of service.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу