Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-fpgr-mg9w-x2hm

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-fp7j-v353-cf72

больше 3 лет назад

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

EPSS: Низкий
github логотип

GHSA-fp74-7pjv-fqcj

больше 3 лет назад

An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via request smuggling.

EPSS: Низкий
github логотип

GHSA-fmg9-cqhf-254r

больше 3 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-fm8v-3mq9-h889

больше 3 лет назад

An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens

EPSS: Низкий
github логотип

GHSA-fm67-vpp9-99gh

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues

EPSS: Низкий
github логотип

GHSA-fjj2-x466-w3hx

около 2 месяцев назад

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-fjgv-pw7x-g797

больше 3 лет назад

GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.

EPSS: Низкий
github логотип

GHSA-fjc3-h6x3-cpx9

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-fj94-q44p-pf8f

больше 3 лет назад

An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method

EPSS: Низкий
github логотип

GHSA-fhrq-2vr4-f65r

больше 3 лет назад

Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics

EPSS: Низкий
github логотип

GHSA-fh9c-h28h-pf65

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-fh7h-m5x3-9v4g

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previously removed malicious maintainer or owner of the child group can still gain access to the group via SSO or a SCIM token to perform actions on the group.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-fh73-gxwx-h999

больше 3 лет назад

GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.

EPSS: Низкий
github логотип

GHSA-fh2j-rw8g-c7f3

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-fgvw-2v52-jhfv

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-ffcr-rwf9-9f8f

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-ff7f-54gm-r4p6

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

EPSS: Низкий
github логотип

GHSA-ff73-cwc3-6v5j

больше 3 лет назад

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

EPSS: Низкий
github логотип

GHSA-ff57-593p-9ffx

больше 3 лет назад

An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the GFM markdown API.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-fpgr-mg9w-x2hm

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVSS3: 9.8
57%
Средний
почти 4 года назад
github логотип
GHSA-fp7j-v353-cf72

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-fp74-7pjv-fqcj

An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via request smuggling.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-fmg9-cqhf-254r

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fm8v-3mq9-h889

An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens

0%
Низкий
больше 3 лет назад
github логотип
GHSA-fm67-vpp9-99gh

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues

0%
Низкий
больше 3 лет назад
github логотип
GHSA-fjj2-x466-w3hx

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.

CVSS3: 8.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-fjgv-pw7x-g797

GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-fjc3-h6x3-cpx9

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-fj94-q44p-pf8f

An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method

0%
Низкий
больше 3 лет назад
github логотип
GHSA-fhrq-2vr4-f65r

Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics

0%
Низкий
больше 3 лет назад
github логотип
GHSA-fh9c-h28h-pf65

An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-fh7h-m5x3-9v4g

An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previously removed malicious maintainer or owner of the child group can still gain access to the group via SSO or a SCIM token to perform actions on the group.

CVSS3: 7.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-fh73-gxwx-h999

GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-fh2j-rw8g-c7f3

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 8.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-fgvw-2v52-jhfv

An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-ffcr-rwf9-9f8f

An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-ff7f-54gm-r4p6

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-ff73-cwc3-6v5j

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-ff57-593p-9ffx

An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the GFM markdown API.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу