Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 995

Количество 5 995

ubuntu логотип

CVE-2023-5332

почти 3 года назад

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2023-5332

почти 3 года назад

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2023-5332

почти 3 года назад

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2023-5332

почти 3 года назад

Patch in third party library Consul requires 'enable-script-checks' to ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2022-3573

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-3573

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-3573

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2021-32823

больше 5 лет назад

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2021-32823

больше 5 лет назад

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2021-32823

больше 5 лет назад

In the bindata RubyGem before version 2.4.10 there is a potential deni ...

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2013-4583

больше 6 лет назад

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2013-4583

больше 6 лет назад

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4 ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2013-4582

больше 6 лет назад

The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to include information from local files into the metadata of a Git repository via the web interface.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2013-4582

больше 6 лет назад

The (1) create_branch, (2) create_tag, (3) import_project, and (4) for ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2013-4581

больше 12 лет назад

GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2013-4581

больше 12 лет назад

GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Ed ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-4546

больше 12 лет назад

The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2013-4546

больше 12 лет назад

The repository import feature in gitlab-shell before 1.7.4, as used in ...

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2013-4490

больше 12 лет назад

The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.

CVSS2: 6.5
EPSS: Средний
debian логотип

CVE-2013-4490

больше 12 лет назад

The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before ...

CVSS2: 6.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-5332

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
1%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-5332

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 8.1
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-5332

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-5332

Patch in third party library Consul requires 'enable-script-checks' to ...

CVSS3: 5.9
1%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-3573

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3573

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3573

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2021-32823

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.

CVSS3: 3.7
2%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-32823

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.

CVSS3: 3.7
2%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-32823

In the bindata RubyGem before version 2.4.10 there is a potential deni ...

CVSS3: 3.7
2%
Низкий
больше 5 лет назад
nvd логотип
CVE-2013-4583

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.

CVSS3: 8.8
2%
Низкий
больше 6 лет назад
debian логотип
CVE-2013-4583

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4 ...

CVSS3: 8.8
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2013-4582

The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to include information from local files into the metadata of a Git repository via the web interface.

CVSS3: 6.5
2%
Низкий
больше 6 лет назад
debian логотип
CVE-2013-4582

The (1) create_branch, (2) create_tag, (3) import_project, and (4) for ...

CVSS3: 6.5
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2013-4581

GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.

CVSS2: 6.8
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-4581

GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Ed ...

CVSS2: 6.8
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4546

The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.

CVSS2: 6.5
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-4546

The repository import feature in gitlab-shell before 1.7.4, as used in ...

CVSS2: 6.5
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4490

The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.

CVSS2: 6.5
42%
Средний
больше 12 лет назад
debian логотип
CVE-2013-4490

The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before ...

CVSS2: 6.5
42%
Средний
больше 12 лет назад

Уязвимостей на страницу