Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 918

Количество 5 918

debian логотип

CVE-2017-0917

больше 8 лет назад

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-0916

больше 8 лет назад

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-0916

больше 8 лет назад

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-0916

больше 8 лет назад

Gitlab Community Edition version 10.3 is vulnerable to a lack of input ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-0915

больше 8 лет назад

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-0915

больше 8 лет назад

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-0915

больше 8 лет назад

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of inp ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-0914

больше 8 лет назад

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-0914

больше 8 лет назад

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-0914

больше 8 лет назад

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2. ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-0882

больше 9 лет назад

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2017-0882

больше 9 лет назад

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2017-0882

больше 9 лет назад

Multiple versions of GitLab expose sensitive user credentials when ass ...

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2016-9469

больше 9 лет назад

Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be exploited by an unauthenticated user. A fix was included in versions 8.14.3, 8.13.8, and 8.12.11, which were released on December 5th 2016 at 3:59 PST. The GitLab versions vulnerable to this are 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1, 8.14.2, and 8.14.2-ee.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2016-9469

больше 9 лет назад

Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be exploited by an unauthenticated user. A fix was included in versions 8.14.3, 8.13.8, and 8.12.11, which were released on December 5th 2016 at 3:59 PST. The GitLab versions vulnerable to this are 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1, 8.14.2, and 8.14.2-ee.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2016-9469

больше 9 лет назад

Multiple versions of GitLab expose a dangerous method to any authentic ...

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2016-9086

больше 9 лет назад

GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files (tar). All GitLab versions prior to 8.13.0 restricted this feature to administrators only. Starting with version 8.13.0 this feature was made available to all users. This feature did not properly check for symbolic links in user-provided archives and therefore it was possible for an authenticated user to retrieve the contents of any file accessible to the GitLab service account. This included sensitive files such as those that contain secret tokens used by the GitLab service to authenticate users. GitLab CE and EE versions 8.13.0 through 8.13.2, 8.12.0 through 8.12.7, 8.11.0 through 8.11.10, 8.10.0 through 8.10.12, and 8.9.0 through 8.9.11 are affected.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2016-9086

больше 9 лет назад

GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files (tar). All GitLab versions prior to 8.13.0 restricted this feature to administrators only. Starting with version 8.13.0 this feature was made available to all users. This feature did not properly check for symbolic links in user-provided archives and therefore it was possible for an authenticated user to retrieve the contents of any file accessible to the GitLab service account. This included sensitive files such as those that contain secret tokens used by the GitLab service to authenticate users. GitLab CE and EE versions 8.13.0 through 8.13.2, 8.12.0 through 8.12.7, 8.11.0 through 8.11.10, 8.10.0 through 8.10.12, and 8.9.0 through 8.9.11 are affected.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2016-9086

больше 9 лет назад

GitLab versions 8.9.x and above contain a critical security flaw in th ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2016-4340

больше 9 лет назад

The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2017-0917

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input ...

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0916

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

CVSS3: 9.8
6%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-0916

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

CVSS3: 9.8
6%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-0916

Gitlab Community Edition version 10.3 is vulnerable to a lack of input ...

CVSS3: 9.8
6%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0915

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVSS3: 9.8
6%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-0915

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVSS3: 9.8
6%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-0915

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of inp ...

CVSS3: 9.8
6%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0914

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.

CVSS3: 7.5
1%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-0914

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.

CVSS3: 7.5
1%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-0914

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2. ...

CVSS3: 7.5
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0882

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

CVSS3: 6.3
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2017-0882

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

CVSS3: 6.3
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2017-0882

Multiple versions of GitLab expose sensitive user credentials when ass ...

CVSS3: 6.3
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-9469

Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be exploited by an unauthenticated user. A fix was included in versions 8.14.3, 8.13.8, and 8.12.11, which were released on December 5th 2016 at 3:59 PST. The GitLab versions vulnerable to this are 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1, 8.14.2, and 8.14.2-ee.

CVSS3: 8.2
2%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-9469

Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be exploited by an unauthenticated user. A fix was included in versions 8.14.3, 8.13.8, and 8.12.11, which were released on December 5th 2016 at 3:59 PST. The GitLab versions vulnerable to this are 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1, 8.14.2, and 8.14.2-ee.

CVSS3: 8.2
2%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-9469

Multiple versions of GitLab expose a dangerous method to any authentic ...

CVSS3: 8.2
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-9086

GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files (tar). All GitLab versions prior to 8.13.0 restricted this feature to administrators only. Starting with version 8.13.0 this feature was made available to all users. This feature did not properly check for symbolic links in user-provided archives and therefore it was possible for an authenticated user to retrieve the contents of any file accessible to the GitLab service account. This included sensitive files such as those that contain secret tokens used by the GitLab service to authenticate users. GitLab CE and EE versions 8.13.0 through 8.13.2, 8.12.0 through 8.12.7, 8.11.0 through 8.11.10, 8.10.0 through 8.10.12, and 8.9.0 through 8.9.11 are affected.

CVSS3: 6.5
5%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-9086

GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files (tar). All GitLab versions prior to 8.13.0 restricted this feature to administrators only. Starting with version 8.13.0 this feature was made available to all users. This feature did not properly check for symbolic links in user-provided archives and therefore it was possible for an authenticated user to retrieve the contents of any file accessible to the GitLab service account. This included sensitive files such as those that contain secret tokens used by the GitLab service to authenticate users. GitLab CE and EE versions 8.13.0 through 8.13.2, 8.12.0 through 8.12.7, 8.11.0 through 8.11.10, 8.10.0 through 8.10.12, and 8.9.0 through 8.9.11 are affected.

CVSS3: 6.5
5%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-9086

GitLab versions 8.9.x and above contain a critical security flaw in th ...

CVSS3: 6.5
5%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-4340

The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.

CVSS3: 8.8
10%
Средний
больше 9 лет назад

Уязвимостей на страницу