Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 918

Количество 5 918

github логотип

GHSA-h38g-w8gh-4m6m

больше 1 года назад

An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-h32m-4g5f-5rv2

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain specific paths on the server. Affected versions are: >=8.8.9, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-h2w4-xw94-vcj3

около 4 лет назад

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-h2vc-rgmf-cp34

8 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted GraphQL queries that bypass query complexity limits.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-h2r9-r9v2-fvwp

больше 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these external services.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-h2q6-mm6m-cfxp

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that could have allowed an authenticated user to access titles of confidential or private issues in public projects due to improper access control in the issue description rendering process.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-h2pr-7jw7-3ghr

около 4 лет назад

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-h2fc-m4gm-6mg8

около 2 лет назад

A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-gxrf-5r9c-xmqq

около 4 лет назад

An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-gxh9-4vgj-w44j

12 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gxcq-53fv-9j43

около 4 лет назад

GitLab EE 10.1 through 12.7.2 allows Information Disclosure.

EPSS: Низкий
github логотип

GHSA-gx75-66mx-pjmm

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions.

EPSS: Низкий
github логотип

GHSA-gx2q-25q6-r3h9

около 4 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that allow-list may be bypassed if a Maintainer uses the 'Invite a group' feature to invite a group that has members that don't comply with domain allow-list.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-gwxm-w4m8-m6mp

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to bypass WebAuthn two-factor authentication and gain unauthorized access to user accounts due to inconsistent input validation in the authentication process.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-gwvc-g4vv-pjx6

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can point a CI/CD Component to an incorrect path and cause the server to exhaust all available memory through an infinite loop and cause Denial of Service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gwr5-7mcm-726j

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.

CVSS3: 8.5
EPSS: Средний
github логотип

GHSA-gw7r-3j53-5c25

почти 4 года назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-gw3x-gpwc-g528

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Uncontrolled Resource Consumption.

EPSS: Низкий
github логотип

GHSA-gw2v-wgmh-28v4

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gvr9-jwjx-g2pq

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by injecting malicious content into vulnerability code flow.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-h38g-w8gh-4m6m

An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 7.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-h32m-4g5f-5rv2

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain specific paths on the server. Affected versions are: >=8.8.9, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

2%
Низкий
около 4 лет назад
github логотип
GHSA-h2w4-xw94-vcj3

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.

1%
Низкий
около 4 лет назад
github логотип
GHSA-h2vc-rgmf-cp34

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted GraphQL queries that bypass query complexity limits.

CVSS3: 7.5
1%
Низкий
8 месяцев назад
github логотип
GHSA-h2r9-r9v2-fvwp

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these external services.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-h2q6-mm6m-cfxp

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that could have allowed an authenticated user to access titles of confidential or private issues in public projects due to improper access control in the issue description rendering process.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-h2pr-7jw7-3ghr

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-h2fc-m4gm-6mg8

A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-gxrf-5r9c-xmqq

An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-gxh9-4vgj-w44j

An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-gxcq-53fv-9j43

GitLab EE 10.1 through 12.7.2 allows Information Disclosure.

1%
Низкий
около 4 лет назад
github логотип
GHSA-gx75-66mx-pjmm

An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions.

1%
Низкий
около 4 лет назад
github логотип
GHSA-gx2q-25q6-r3h9

An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that allow-list may be bypassed if a Maintainer uses the 'Invite a group' feature to invite a group that has members that don't comply with domain allow-list.

CVSS3: 2.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-gwxm-w4m8-m6mp

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to bypass WebAuthn two-factor authentication and gain unauthorized access to user accounts due to inconsistent input validation in the authentication process.

CVSS3: 6.8
0%
Низкий
4 месяца назад
github логотип
GHSA-gwvc-g4vv-pjx6

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can point a CI/CD Component to an incorrect path and cause the server to exhaust all available memory through an infinite loop and cause Denial of Service.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-gwr5-7mcm-726j

An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.

CVSS3: 8.5
23%
Средний
больше 2 лет назад
github логотип
GHSA-gw7r-3j53-5c25

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 4.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-gw3x-gpwc-g528

An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Uncontrolled Resource Consumption.

1%
Низкий
около 4 лет назад
github логотип
GHSA-gw2v-wgmh-28v4

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-gvr9-jwjx-g2pq

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by injecting malicious content into vulnerability code flow.

CVSS3: 7.3
0%
Низкий
6 месяцев назад

Уязвимостей на страницу