Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-fr4g-hmc7-w66h

почти 4 года назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fpgr-mg9w-x2hm

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-fp7j-v353-cf72

почти 4 года назад

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

EPSS: Низкий
github логотип

GHSA-fp74-7pjv-fqcj

почти 4 года назад

An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via request smuggling.

EPSS: Низкий
github логотип

GHSA-fmg9-cqhf-254r

больше 3 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-fm8v-3mq9-h889

почти 4 года назад

An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens

EPSS: Низкий
github логотип

GHSA-fm67-vpp9-99gh

почти 4 года назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues

EPSS: Низкий
github логотип

GHSA-fjj2-x466-w3hx

4 месяца назад

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-fjgv-pw7x-g797

почти 4 года назад

GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.

EPSS: Низкий
github логотип

GHSA-fjc3-h6x3-cpx9

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-fj94-q44p-pf8f

почти 4 года назад

An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method

EPSS: Низкий
github логотип

GHSA-fhrq-2vr4-f65r

почти 4 года назад

Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics

EPSS: Низкий
github логотип

GHSA-fh9c-h28h-pf65

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-fh7h-m5x3-9v4g

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previously removed malicious maintainer or owner of the child group can still gain access to the group via SSO or a SCIM token to perform actions on the group.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-fh73-gxwx-h999

почти 4 года назад

GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.

EPSS: Низкий
github логотип

GHSA-fh2j-rw8g-c7f3

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-fgvw-2v52-jhfv

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-ffcr-rwf9-9f8f

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-ff7f-54gm-r4p6

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

EPSS: Низкий
github логотип

GHSA-ff73-cwc3-6v5j

почти 4 года назад

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-fr4g-hmc7-w66h

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-fpgr-mg9w-x2hm

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVSS3: 9.8
57%
Средний
около 4 лет назад
github логотип
GHSA-fp7j-v353-cf72

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

0%
Низкий
почти 4 года назад
github логотип
GHSA-fp74-7pjv-fqcj

An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via request smuggling.

0%
Низкий
почти 4 года назад
github логотип
GHSA-fmg9-cqhf-254r

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fm8v-3mq9-h889

An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens

0%
Низкий
почти 4 года назад
github логотип
GHSA-fm67-vpp9-99gh

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues

0%
Низкий
почти 4 года назад
github логотип
GHSA-fjj2-x466-w3hx

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.

CVSS3: 8.7
0%
Низкий
4 месяца назад
github логотип
GHSA-fjgv-pw7x-g797

GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.

0%
Низкий
почти 4 года назад
github логотип
GHSA-fjc3-h6x3-cpx9

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-fj94-q44p-pf8f

An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method

0%
Низкий
почти 4 года назад
github логотип
GHSA-fhrq-2vr4-f65r

Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics

0%
Низкий
почти 4 года назад
github логотип
GHSA-fh9c-h28h-pf65

An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-fh7h-m5x3-9v4g

An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previously removed malicious maintainer or owner of the child group can still gain access to the group via SSO or a SCIM token to perform actions on the group.

CVSS3: 7.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-fh73-gxwx-h999

GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.

0%
Низкий
почти 4 года назад
github логотип
GHSA-fh2j-rw8g-c7f3

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 8.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-fgvw-2v52-jhfv

An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-ffcr-rwf9-9f8f

An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-ff7f-54gm-r4p6

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

0%
Низкий
почти 4 года назад
github логотип
GHSA-ff73-cwc3-6v5j

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу