Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 4 556

Количество 4 556

github логотип

GHSA-wrm3-h327-j8wh

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD variables using the custom project templates.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-wqxm-qp29-hp7c

больше 2 лет назад

In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wqrm-4jcg-5rjc

около 3 лет назад

An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.

EPSS: Низкий
github логотип

GHSA-wq8m-964x-6vr4

около 1 года назад

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-wq7h-qgq6-wjqm

около 2 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the merge request page via project import.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-wpxf-3mm2-76f8

4 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-wpj8-2grx-f965

больше 1 года назад

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-wmqm-jhj6-rhr7

около 3 лет назад

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-wmfr-vxm2-px6q

около 3 лет назад

GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2).

EPSS: Низкий
github логотип

GHSA-wmcm-x8vj-qqp7

около 3 лет назад

GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-wm64-hhrx-w2h7

около 2 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter using rouge can block for a long time in Sidekiq jobs without any timeout.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wjpf-p2m9-5wmv

около 3 лет назад

In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-whxf-7mv4-g5wm

около 3 лет назад

An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. When group SAML SSO is configured, the SCIM feature (available only on Premium+ subscriptions) may allow any owner of a Premium group to invite arbitrary users through their username and email, then change those users' email addresses via SCIM to an attacker controlled email address and thus - in the absence of 2FA - take over those accounts. It is also possible for the attacker to change the display name and username of the targeted account.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-wh94-79gr-cv69

около 3 лет назад

A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added.

EPSS: Низкий
github логотип

GHSA-wh39-vq4j-xpj4

около 3 лет назад

GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-wgh9-p42c-pq7h

около 3 лет назад

Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-wggh-9jhq-9h7x

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the GraphQL API.

EPSS: Низкий
github логотип

GHSA-wg76-c5w5-h7xg

около 3 лет назад

Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.

EPSS: Низкий
github логотип

GHSA-wg27-v6fh-mh3j

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could potentially lead a victim to download malicious code.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-wfj3-6j6g-rpwx

около 3 лет назад

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-wrm3-h327-j8wh

An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD variables using the custom project templates.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-wqxm-qp29-hp7c

In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-wqrm-4jcg-5rjc

An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.

0%
Низкий
около 3 лет назад
github логотип
GHSA-wq8m-964x-6vr4

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVSS3: 4.4
0%
Низкий
около 1 года назад
github логотип
GHSA-wq7h-qgq6-wjqm

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the merge request page via project import.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-wpxf-3mm2-76f8

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.

CVSS3: 8.7
0%
Низкий
4 месяца назад
github логотип
GHSA-wpj8-2grx-f965

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

CVSS3: 7.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-wmqm-jhj6-rhr7

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-wmfr-vxm2-px6q

GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2).

0%
Низкий
около 3 лет назад
github логотип
GHSA-wmcm-x8vj-qqp7

GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component.

CVSS3: 9.8
40%
Средний
около 3 лет назад
github логотип
GHSA-wm64-hhrx-w2h7

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter using rouge can block for a long time in Sidekiq jobs without any timeout.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-wjpf-p2m9-5wmv

In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-whxf-7mv4-g5wm

An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. When group SAML SSO is configured, the SCIM feature (available only on Premium+ subscriptions) may allow any owner of a Premium group to invite arbitrary users through their username and email, then change those users' email addresses via SCIM to an attacker controlled email address and thus - in the absence of 2FA - take over those accounts. It is also possible for the attacker to change the display name and username of the targeted account.

CVSS3: 8.8
12%
Средний
около 3 лет назад
github логотип
GHSA-wh94-79gr-cv69

A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added.

0%
Низкий
около 3 лет назад
github логотип
GHSA-wh39-vq4j-xpj4

GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.

0%
Низкий
около 3 лет назад
github логотип
GHSA-wgh9-p42c-pq7h

Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-wggh-9jhq-9h7x

An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the GraphQL API.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wg76-c5w5-h7xg

Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.

0%
Низкий
около 3 лет назад
github логотип
GHSA-wg27-v6fh-mh3j

An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could potentially lead a victim to download malicious code.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-wfj3-6j6g-rpwx

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

2%
Низкий
около 3 лет назад

Уязвимостей на страницу