Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 332

Количество 5 332

github логотип

GHSA-h3pp-hqpg-9qmw

больше 1 года назад

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-h38g-w8gh-4m6m

10 месяцев назад

An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-h32m-4g5f-5rv2

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain specific paths on the server. Affected versions are: >=8.8.9, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-h2w4-xw94-vcj3

больше 3 лет назад

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-h2vc-rgmf-cp34

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted GraphQL queries that bypass query complexity limits.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-h2r9-r9v2-fvwp

почти 4 года назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these external services.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-h2pr-7jw7-3ghr

больше 3 лет назад

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-h2fc-m4gm-6mg8

больше 1 года назад

A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-gxrf-5r9c-xmqq

больше 3 лет назад

An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-gxh9-4vgj-w44j

6 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gxcq-53fv-9j43

больше 3 лет назад

GitLab EE 10.1 through 12.7.2 allows Information Disclosure.

EPSS: Низкий
github логотип

GHSA-gx75-66mx-pjmm

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions.

EPSS: Низкий
github логотип

GHSA-gx2q-25q6-r3h9

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that allow-list may be bypassed if a Maintainer uses the 'Invite a group' feature to invite a group that has members that don't comply with domain allow-list.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-gwvc-g4vv-pjx6

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can point a CI/CD Component to an incorrect path and cause the server to exhaust all available memory through an infinite loop and cause Denial of Service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gwr5-7mcm-726j

почти 2 года назад

An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-gw7r-3j53-5c25

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-gw3x-gpwc-g528

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Uncontrolled Resource Consumption.

EPSS: Низкий
github логотип

GHSA-gw2v-wgmh-28v4

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gvg6-gvpx-66f6

около 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project access for Security policy bot.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-gr98-7cg9-j7c7

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-h3pp-hqpg-9qmw

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-h38g-w8gh-4m6m

An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 7.7
0%
Низкий
10 месяцев назад
github логотип
GHSA-h32m-4g5f-5rv2

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain specific paths on the server. Affected versions are: >=8.8.9, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h2w4-xw94-vcj3

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h2vc-rgmf-cp34

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted GraphQL queries that bypass query complexity limits.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-h2r9-r9v2-fvwp

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these external services.

CVSS3: 6.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-h2pr-7jw7-3ghr

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-h2fc-m4gm-6mg8

A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-gxrf-5r9c-xmqq

An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-gxh9-4vgj-w44j

An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-gxcq-53fv-9j43

GitLab EE 10.1 through 12.7.2 allows Information Disclosure.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-gx75-66mx-pjmm

An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-gx2q-25q6-r3h9

An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that allow-list may be bypassed if a Maintainer uses the 'Invite a group' feature to invite a group that has members that don't comply with domain allow-list.

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-gwvc-g4vv-pjx6

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can point a CI/CD Component to an incorrect path and cause the server to exhaust all available memory through an infinite loop and cause Denial of Service.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-gwr5-7mcm-726j

An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.

CVSS3: 8.5
4%
Низкий
почти 2 года назад
github логотип
GHSA-gw7r-3j53-5c25

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-gw3x-gpwc-g528

An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Uncontrolled Resource Consumption.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-gw2v-wgmh-28v4

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-gvg6-gvpx-66f6

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project access for Security policy bot.

CVSS3: 4.4
0%
Низкий
около 1 года назад
github логотип
GHSA-gr98-7cg9-j7c7

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
1%
Низкий
больше 1 года назад

Уязвимостей на страницу