Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 918

Количество 5 918

github логотип

GHSA-gcqh-vjgw-r524

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by modifying the site.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-gcj2-4jcm-vgjg

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's email address as an unverified secondary email.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-gchc-78gm-5379

больше 3 лет назад

Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-gcgf-w628-jq5c

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose confidential issue titles due to improper filtering under certain circumstances.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-gc94-7v9h-xfq8

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could exfiltrate a Datadog integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-gc6j-24mw-538j

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting with 12.9. GitLab was vulnerable to a stored XSS if scoped labels were used.

EPSS: Низкий
github логотип

GHSA-gc5m-gc6j-fr9q

около 4 лет назад

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are stored in plain-text in Redis which allows attacker with Redis access to authenticate as any user that has a session stored in Redis

EPSS: Низкий
github логотип

GHSA-g9pv-f88j-p6rr

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-g9jp-p8w6-7f2q

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they import members from another project that those other users are Owners of.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-g93f-rhw4-8mj3

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-g927-v8jh-hjfq

около 4 лет назад

An Insecure Permissions issue (issue 3 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Guests of a project were allowed to see Related Branches created for an issue.

EPSS: Низкий
github логотип

GHSA-g8xq-pp9p-qgx8

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. It was possible to add a branch with an ambiguous name that could be used to social engineer users.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-g8v2-8wgj-gwx8

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could cause a denial of service with requests for diff files on a commit or merge request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-g8p8-2v2x-8mhv

около 4 лет назад

Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-g8j3-2rcp-jrhm

больше 4 лет назад

A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands

EPSS: Низкий
github логотип

GHSA-g8hg-rjf5-vfrm

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, where dependency proxy credentials are retained in graphql Logs.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-g884-f5hg-pgw8

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-g7wj-h75w-2cr7

около 4 лет назад

Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-g7wf-h5q3-9vf4

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

EPSS: Низкий
github логотип

GHSA-g797-r4r7-wp94

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially bypass authentication controls, allowing unauthorized access to streaming results.

CVSS3: 4.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-gcqh-vjgw-r524

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by modifying the site.

CVSS3: 3.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-gcj2-4jcm-vgjg

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's email address as an unverified secondary email.

CVSS3: 8.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-gchc-78gm-5379

Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-gcgf-w628-jq5c

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose confidential issue titles due to improper filtering under certain circumstances.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-gc94-7v9h-xfq8

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could exfiltrate a Datadog integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-gc6j-24mw-538j

An issue has been discovered in GitLab affecting all versions starting with 12.9. GitLab was vulnerable to a stored XSS if scoped labels were used.

1%
Низкий
около 4 лет назад
github логотип
GHSA-gc5m-gc6j-fr9q

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are stored in plain-text in Redis which allows attacker with Redis access to authenticate as any user that has a session stored in Redis

0%
Низкий
около 4 лет назад
github логотип
GHSA-g9pv-f88j-p6rr

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation.

CVSS3: 8
0%
Низкий
3 месяца назад
github логотип
GHSA-g9jp-p8w6-7f2q

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they import members from another project that those other users are Owners of.

CVSS3: 4.4
1%
Низкий
около 3 лет назад
github логотип
GHSA-g93f-rhw4-8mj3

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-g927-v8jh-hjfq

An Insecure Permissions issue (issue 3 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Guests of a project were allowed to see Related Branches created for an issue.

1%
Низкий
около 4 лет назад
github логотип
GHSA-g8xq-pp9p-qgx8

An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. It was possible to add a branch with an ambiguous name that could be used to social engineer users.

CVSS3: 4.6
1%
Низкий
больше 3 лет назад
github логотип
GHSA-g8v2-8wgj-gwx8

An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could cause a denial of service with requests for diff files on a commit or merge request.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-g8p8-2v2x-8mhv

Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.

CVSS3: 2.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-g8j3-2rcp-jrhm

A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands

1%
Низкий
больше 4 лет назад
github логотип
GHSA-g8hg-rjf5-vfrm

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, where dependency proxy credentials are retained in graphql Logs.

CVSS3: 4
0%
Низкий
почти 2 года назад
github логотип
GHSA-g884-f5hg-pgw8

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

CVSS3: 5.3
4%
Низкий
больше 2 лет назад
github логотип
GHSA-g7wj-h75w-2cr7

Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-g7wf-h5q3-9vf4

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

1%
Низкий
около 4 лет назад
github логотип
GHSA-g797-r4r7-wp94

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially bypass authentication controls, allowing unauthorized access to streaming results.

CVSS3: 4.2
0%
Низкий
больше 1 года назад

Уязвимостей на страницу