Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 918

Количество 5 918

github логотип

GHSA-h92q-g5vv-9g2c

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-h8wc-8hmg-pcc9

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to access confidential issue details due to incorrect authorization checks.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-h8q5-vxrg-qgmf

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed a user to use invalidated or incorrectly scoped credentials to access Virtual Registries under certain conditions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-h8h7-r99g-m28c

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-h7pc-v4hv-wjwm

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. Its User Interface has a Misrepresentation of Critical Information.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-h79h-c7qx-243v

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-h782-mprg-p5xv

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible to trigger a DoS attack by uploading a malicious nuget package.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-h743-v64g-4f2g

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab reveals if a user has enabled two-factor authentication on their account in the HTML source, to unauthenticated users.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-h6w2-q947-gwv4

около 4 лет назад

A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1

EPSS: Низкий
github логотип

GHSA-h6qj-3xrq-vxh8

12 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-h62c-3g8w-9vjr

около 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. Arbitrary access to the titles of an private specific references could be leaked through the service-desk custom email template.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-h5pw-h3j7-cj7f

24 дня назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web interface differed from the content available for download, due to improper handling of Git reference name resolution.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-h5fq-66m8-wp4v

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 1 of 5).

EPSS: Низкий
github логотип

GHSA-h4mq-8rq4-7m7x

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-h453-7rrx-q6j5

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-h43r-6wwr-vj3g

около 4 лет назад

GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the issue was made Confidential.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-h42v-738f-q57f

около 4 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.

EPSS: Низкий
github логотип

GHSA-h3v8-2pff-ph95

около 4 лет назад

GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-h3r9-rg3q-7f5f

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to edit labels description by an unauthorised user.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-h3pp-hqpg-9qmw

около 2 лет назад

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-h92q-g5vv-9g2c

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations.

CVSS3: 2.7
0%
Низкий
4 месяца назад
github логотип
GHSA-h8wc-8hmg-pcc9

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to access confidential issue details due to incorrect authorization checks.

CVSS3: 3.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-h8q5-vxrg-qgmf

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed a user to use invalidated or incorrectly scoped credentials to access Virtual Registries under certain conditions.

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-h8h7-r99g-m28c

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.

CVSS3: 4.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-h7pc-v4hv-wjwm

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. Its User Interface has a Misrepresentation of Critical Information.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-h79h-c7qx-243v

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-h782-mprg-p5xv

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible to trigger a DoS attack by uploading a malicious nuget package.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-h743-v64g-4f2g

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab reveals if a user has enabled two-factor authentication on their account in the HTML source, to unauthenticated users.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-h6w2-q947-gwv4

A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1

2%
Низкий
около 4 лет назад
github логотип
GHSA-h6qj-3xrq-vxh8

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.

CVSS3: 8.7
0%
Низкий
12 месяцев назад
github логотип
GHSA-h62c-3g8w-9vjr

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. Arbitrary access to the titles of an private specific references could be leaked through the service-desk custom email template.

CVSS3: 3.1
0%
Низкий
около 1 года назад
github логотип
GHSA-h5pw-h3j7-cj7f

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web interface differed from the content available for download, due to improper handling of Git reference name resolution.

CVSS3: 3.5
0%
Низкий
24 дня назад
github логотип
GHSA-h5fq-66m8-wp4v

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 1 of 5).

2%
Низкий
около 4 лет назад
github логотип
GHSA-h4mq-8rq4-7m7x

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-h453-7rrx-q6j5

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-h43r-6wwr-vj3g

GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the issue was made Confidential.

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-h42v-738f-q57f

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.

1%
Низкий
около 4 лет назад
github логотип
GHSA-h3v8-2pff-ph95

GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-h3r9-rg3q-7f5f

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to edit labels description by an unauthorised user.

CVSS3: 3.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-h3pp-hqpg-9qmw

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level.

CVSS3: 4.3
0%
Низкий
около 2 лет назад

Уязвимостей на страницу