Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 918

Количество 5 918

github логотип

GHSA-g6rr-7jqw-c6hc

около 1 года назад

An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-g68w-w4h2-fr59

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with minimal workspace permissions to obtain installation credentials and impersonate the GitLab app due to improper authorization checks.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-g5rc-vv3j-cq5q

около 4 лет назад

An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners

EPSS: Низкий
github логотип

GHSA-g5qp-3jx2-p69r

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could inject HMTL into the child item search potentially leading to XSS in certain situations.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-g5mf-xw7v-rmr9

около 4 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9.

EPSS: Низкий
github логотип

GHSA-g5f7-9xpc-633r

около 4 лет назад

An issue has been discovered in GitLab affecting all versions. Improper access control allows unauthorised users to access project details using Graphql.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-g5f4-f74v-9j97

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of information which allowed an user to authenticate without a personal access token.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-g5cm-j62r-w7f5

почти 4 года назад

Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-g592-5fxh-qhrv

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Insufficient Visual Distinction of Homoglyphs Presented to a User. IDN homographs and RTLO characters are rendered to unicode, which could be used for social engineering.

EPSS: Низкий
github логотип

GHSA-g4wv-rqvc-h4jp

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks.

EPSS: Низкий
github логотип

GHSA-g4px-p74v-q4c7

около 4 лет назад

Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9.

EPSS: Низкий
github логотип

GHSA-g4c2-hhjc-4hgg

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of [CVE-2023-3932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3932) showing additional impact.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-g3q8-7g5m-j8cw

около 4 лет назад

GitLab EE 11.0 and later through 12.7.2 allows XSS.

EPSS: Низкий
github логотип

GHSA-g3jp-2gfc-xjq6

больше 3 лет назад

A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-g3hq-7735-4x6v

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthorized user with Developer-role permissions to set pipeline variables for manually triggered jobs under certain conditions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-g349-hgx7-9cj9

10 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that allows unauthenticated users to cause a Denial of Service (DoS) condition while uploading specifically crafted large JSON files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-fx2p-8vp5-7hx7

около 4 лет назад

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to an authorization issue that allowed users to view confidential issue and merge request titles of other projects.

EPSS: Низкий
github логотип

GHSA-fwr7-9543-4584

около 4 лет назад

Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-fwjq-556c-7hwm

около 1 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-fvw3-2rq4-x8qv

около 4 лет назад

GitLab Community and Enterprise Edition before 11.3.14, 11.4.x before 11.4.12, and 11.5.x before 11.5.5 allows Directory Traversal.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-g6rr-7jqw-c6hc

An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-g68w-w4h2-fr59

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with minimal workspace permissions to obtain installation credentials and impersonate the GitLab app due to improper authorization checks.

CVSS3: 8.1
0%
Низкий
4 месяца назад
github логотип
GHSA-g5rc-vv3j-cq5q

An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners

1%
Низкий
около 4 лет назад
github логотип
GHSA-g5qp-3jx2-p69r

An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could inject HMTL into the child item search potentially leading to XSS in certain situations.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-g5mf-xw7v-rmr9

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9.

1%
Низкий
около 4 лет назад
github логотип
GHSA-g5f7-9xpc-633r

An issue has been discovered in GitLab affecting all versions. Improper access control allows unauthorised users to access project details using Graphql.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-g5f4-f74v-9j97

An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of information which allowed an user to authenticate without a personal access token.

CVSS3: 3.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-g5cm-j62r-w7f5

Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests

CVSS3: 7.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-g592-5fxh-qhrv

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Insufficient Visual Distinction of Homoglyphs Presented to a User. IDN homographs and RTLO characters are rendered to unicode, which could be used for social engineering.

1%
Низкий
около 4 лет назад
github логотип
GHSA-g4wv-rqvc-h4jp

An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks.

1%
Низкий
около 4 лет назад
github логотип
GHSA-g4px-p74v-q4c7

Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9.

1%
Низкий
около 4 лет назад
github логотип
GHSA-g4c2-hhjc-4hgg

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of [CVE-2023-3932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3932) showing additional impact.

CVSS3: 9.6
8%
Низкий
почти 3 года назад
github логотип
GHSA-g3q8-7g5m-j8cw

GitLab EE 11.0 and later through 12.7.2 allows XSS.

1%
Низкий
около 4 лет назад
github логотип
GHSA-g3jp-2gfc-xjq6

A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-g3hq-7735-4x6v

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthorized user with Developer-role permissions to set pipeline variables for manually triggered jobs under certain conditions.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-g349-hgx7-9cj9

An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that allows unauthenticated users to cause a Denial of Service (DoS) condition while uploading specifically crafted large JSON files.

CVSS3: 7.5
1%
Низкий
10 месяцев назад
github логотип
GHSA-fx2p-8vp5-7hx7

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to an authorization issue that allowed users to view confidential issue and merge request titles of other projects.

2%
Низкий
около 4 лет назад
github логотип
GHSA-fwr7-9543-4584

Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.

CVSS3: 7.2
1%
Низкий
около 4 лет назад
github логотип
GHSA-fwjq-556c-7hwm

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows.

CVSS3: 8.6
0%
Низкий
около 1 месяца назад
github логотип
GHSA-fvw3-2rq4-x8qv

GitLab Community and Enterprise Edition before 11.3.14, 11.4.x before 11.4.12, and 11.5.x before 11.5.5 allows Directory Traversal.

CVSS3: 7.5
2%
Низкий
около 4 лет назад

Уязвимостей на страницу