Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-h963-mpc3-j9g4

почти 4 года назад

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

EPSS: Низкий
github логотип

GHSA-h93x-rrp4-r26c

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 11.9 and later through 12.0.2. GitLab Snippets were vulnerable to an authorization issue that allowed unauthorized users to add comments to a private snippet. It allows authentication bypass.

EPSS: Низкий
github логотип

GHSA-h93h-vj2c-pxf9

почти 4 года назад

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

EPSS: Низкий
github логотип

GHSA-h8h7-r99g-m28c

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-h7pc-v4hv-wjwm

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. Its User Interface has a Misrepresentation of Critical Information.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-h79h-c7qx-243v

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-h782-mprg-p5xv

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible to trigger a DoS attack by uploading a malicious nuget package.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-h743-v64g-4f2g

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab reveals if a user has enabled two-factor authentication on their account in the HTML source, to unauthenticated users.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-h6w2-q947-gwv4

почти 4 года назад

A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1

EPSS: Низкий
github логотип

GHSA-h6qj-3xrq-vxh8

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-h62c-3g8w-9vjr

9 месяцев назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. Arbitrary access to the titles of an private specific references could be leaked through the service-desk custom email template.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-h5fq-66m8-wp4v

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 1 of 5).

EPSS: Низкий
github логотип

GHSA-h4mq-8rq4-7m7x

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-h453-7rrx-q6j5

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-h43r-6wwr-vj3g

почти 4 года назад

GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the issue was made Confidential.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-h42v-738f-q57f

почти 4 года назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.

EPSS: Низкий
github логотип

GHSA-h3v8-2pff-ph95

почти 4 года назад

GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-h3r9-rg3q-7f5f

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to edit labels description by an unauthorised user.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-h3pp-hqpg-9qmw

больше 1 года назад

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-h38g-w8gh-4m6m

11 месяцев назад

An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-h963-mpc3-j9g4

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

0%
Низкий
почти 4 года назад
github логотип
GHSA-h93x-rrp4-r26c

An issue was discovered in GitLab Community and Enterprise Edition 11.9 and later through 12.0.2. GitLab Snippets were vulnerable to an authorization issue that allowed unauthorized users to add comments to a private snippet. It allows authentication bypass.

0%
Низкий
почти 4 года назад
github логотип
GHSA-h93h-vj2c-pxf9

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

0%
Низкий
почти 4 года назад
github логотип
GHSA-h8h7-r99g-m28c

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.

CVSS3: 4.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-h7pc-v4hv-wjwm

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. Its User Interface has a Misrepresentation of Critical Information.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-h79h-c7qx-243v

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-h782-mprg-p5xv

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible to trigger a DoS attack by uploading a malicious nuget package.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-h743-v64g-4f2g

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab reveals if a user has enabled two-factor authentication on their account in the HTML source, to unauthenticated users.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-h6w2-q947-gwv4

A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1

0%
Низкий
почти 4 года назад
github логотип
GHSA-h6qj-3xrq-vxh8

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.

CVSS3: 8.7
0%
Низкий
8 месяцев назад
github логотип
GHSA-h62c-3g8w-9vjr

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. Arbitrary access to the titles of an private specific references could be leaked through the service-desk custom email template.

CVSS3: 3.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-h5fq-66m8-wp4v

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 1 of 5).

0%
Низкий
почти 4 года назад
github логотип
GHSA-h4mq-8rq4-7m7x

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-h453-7rrx-q6j5

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-h43r-6wwr-vj3g

GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the issue was made Confidential.

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-h42v-738f-q57f

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.

0%
Низкий
почти 4 года назад
github логотип
GHSA-h3v8-2pff-ph95

GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-h3r9-rg3q-7f5f

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to edit labels description by an unauthorised user.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-h3pp-hqpg-9qmw

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-h38g-w8gh-4m6m

An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 7.7
0%
Низкий
11 месяцев назад

Уязвимостей на страницу