Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 943

Количество 5 943

ubuntu логотип

CVE-2018-17536

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the merge request page via project import.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-17536

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the merge request page via project import.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-17536

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2018-17455

больше 3 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-17455

больше 3 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-17455

больше 3 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2018-17454

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the issue details screen.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-17454

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the issue details screen.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-17454

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2018-17453

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2018-17453

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2018-17453

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2018-17452

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2018-17452

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-17452

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2018-17451

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-17451

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-17451

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2018-17450

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2018-17450

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-17536

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the merge request page via project import.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-17536

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the merge request page via project import.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2018-17536

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2018-17455

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-17455

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2018-17455

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11 ...

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2018-17454

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the issue details screen.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-17454

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the issue details screen.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2018-17454

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2018-17453

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-17453

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2018-17453

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2018-17452

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-17452

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2018-17452

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2018-17451

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-17451

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2018-17451

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2018-17450

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-17450

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу