Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-gc94-7v9h-xfq8

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could exfiltrate a Datadog integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-gc6j-24mw-538j

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting with 12.9. GitLab was vulnerable to a stored XSS if scoped labels were used.

EPSS: Низкий
github логотип

GHSA-gc5m-gc6j-fr9q

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are stored in plain-text in Redis which allows attacker with Redis access to authenticate as any user that has a session stored in Redis

EPSS: Низкий
github логотип

GHSA-g9jp-p8w6-7f2q

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they import members from another project that those other users are Owners of.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-g93f-rhw4-8mj3

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-g927-v8jh-hjfq

больше 3 лет назад

An Insecure Permissions issue (issue 3 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Guests of a project were allowed to see Related Branches created for an issue.

EPSS: Низкий
github логотип

GHSA-g8xq-pp9p-qgx8

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. It was possible to add a branch with an ambiguous name that could be used to social engineer users.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-g8v2-8wgj-gwx8

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could cause a denial of service with requests for diff files on a commit or merge request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-g8p8-2v2x-8mhv

больше 3 лет назад

Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-g8j3-2rcp-jrhm

около 4 лет назад

A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands

EPSS: Низкий
github логотип

GHSA-g8hg-rjf5-vfrm

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, where dependency proxy credentials are retained in graphql Logs.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-g884-f5hg-pgw8

около 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-g7wj-h75w-2cr7

больше 3 лет назад

Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-g7wf-h5q3-9vf4

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

EPSS: Низкий
github логотип

GHSA-g797-r4r7-wp94

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially bypass authentication controls, allowing unauthorized access to streaming results.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-g6rr-7jqw-c6hc

8 месяцев назад

An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-g5rc-vv3j-cq5q

больше 3 лет назад

An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners

EPSS: Низкий
github логотип

GHSA-g5qp-3jx2-p69r

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could inject HMTL into the child item search potentially leading to XSS in certain situations.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-g5mf-xw7v-rmr9

больше 3 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9.

EPSS: Низкий
github логотип

GHSA-g5f7-9xpc-633r

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions. Improper access control allows unauthorised users to access project details using Graphql.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-gc94-7v9h-xfq8

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could exfiltrate a Datadog integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-gc6j-24mw-538j

An issue has been discovered in GitLab affecting all versions starting with 12.9. GitLab was vulnerable to a stored XSS if scoped labels were used.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-gc5m-gc6j-fr9q

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are stored in plain-text in Redis which allows attacker with Redis access to authenticate as any user that has a session stored in Redis

0%
Низкий
больше 3 лет назад
github логотип
GHSA-g9jp-p8w6-7f2q

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they import members from another project that those other users are Owners of.

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-g93f-rhw4-8mj3

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-g927-v8jh-hjfq

An Insecure Permissions issue (issue 3 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Guests of a project were allowed to see Related Branches created for an issue.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-g8xq-pp9p-qgx8

An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. It was possible to add a branch with an ambiguous name that could be used to social engineer users.

CVSS3: 4.6
1%
Низкий
почти 3 года назад
github логотип
GHSA-g8v2-8wgj-gwx8

An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could cause a denial of service with requests for diff files on a commit or merge request.

CVSS3: 7.5
1%
Низкий
около 1 года назад
github логотип
GHSA-g8p8-2v2x-8mhv

Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-g8j3-2rcp-jrhm

A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands

0%
Низкий
около 4 лет назад
github логотип
GHSA-g8hg-rjf5-vfrm

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, where dependency proxy credentials are retained in graphql Logs.

CVSS3: 4
0%
Низкий
больше 1 года назад
github логотип
GHSA-g884-f5hg-pgw8

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

CVSS3: 5.3
26%
Средний
около 2 лет назад
github логотип
GHSA-g7wj-h75w-2cr7

Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-g7wf-h5q3-9vf4

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-g797-r4r7-wp94

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially bypass authentication controls, allowing unauthorized access to streaming results.

CVSS3: 4.2
0%
Низкий
около 1 года назад
github логотип
GHSA-g6rr-7jqw-c6hc

An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-g5rc-vv3j-cq5q

An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners

0%
Низкий
больше 3 лет назад
github логотип
GHSA-g5qp-3jx2-p69r

An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could inject HMTL into the child item search potentially leading to XSS in certain situations.

CVSS3: 5.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-g5mf-xw7v-rmr9

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-g5f7-9xpc-633r

An issue has been discovered in GitLab affecting all versions. Improper access control allows unauthorised users to access project details using Graphql.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу