Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-f5vg-g8qw-8p89

больше 3 лет назад

An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-f5r5-77wf-xx6h

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-f4ff-rc49-g8hc

почти 3 года назад

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-f48g-wqmg-9r45

больше 1 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause catastrophic backtracking while parsing results from Elasticsearch.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-f435-r8xf-rc9w

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature.

EPSS: Низкий
github логотип

GHSA-f3wg-5hg2-8j39

почти 3 года назад

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions, an attacker may be able to map a private email of a GitLab user to their GitLab account on an instance.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-f3mf-g3hh-m9vw

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled.

EPSS: Низкий
github логотип

GHSA-f3jj-mgwg-pc9w

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information Exposure Through an Error Message.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-f3g5-424c-vfvp

больше 3 лет назад

Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner is calling from outside the allowed IP range

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-f3cp-f6ph-xxhj

больше 3 лет назад

In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s password via the change password function. There is a rate limit in place, but the attack may still be conducted by stealing the session id from the physical compromise of the account and splitting the attack over several IP addresses and passing in the compromised session value from these various locations.

EPSS: Низкий
github логотип

GHSA-f2h5-25cx-h2f5

больше 3 лет назад

The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-f28j-grw4-6ggj

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-cxxv-5c8r-2cfh

около 4 лет назад

Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-cxxf-6583-j227

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-cxqh-7ch8-jx2g

11 месяцев назад

An issue has been discovered in the GitLab Duo with Amazon Q affecting all versions from 17.8 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A specifically crafted issue could manipulate AI-assisted development features to potentially expose sensitive project data to unauthorized users.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-cxjq-5xjf-cmp7

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-cxfq-987j-wpfw

почти 4 года назад

Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-cxfp-vwqp-ghxf

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn't enabled by default.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-cxfj-qcv7-fx7w

больше 3 лет назад

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

EPSS: Низкий
github логотип

GHSA-cx75-44jc-g7gv

больше 3 лет назад

An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-f5vg-g8qw-8p89

An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-f5r5-77wf-xx6h

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.

CVSS3: 8.2
0%
Низкий
около 1 года назад
github логотип
GHSA-f4ff-rc49-g8hc

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-f48g-wqmg-9r45

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause catastrophic backtracking while parsing results from Elasticsearch.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-f435-r8xf-rc9w

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-f3wg-5hg2-8j39

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions, an attacker may be able to map a private email of a GitLab user to their GitLab account on an instance.

CVSS3: 3.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-f3mf-g3hh-m9vw

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-f3jj-mgwg-pc9w

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information Exposure Through an Error Message.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-f3g5-424c-vfvp

Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner is calling from outside the allowed IP range

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-f3cp-f6ph-xxhj

In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s password via the change password function. There is a rate limit in place, but the attack may still be conducted by stealing the session id from the physical compromise of the account and splitting the attack over several IP addresses and passing in the compromised session value from these various locations.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-f2h5-25cx-h2f5

The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-f28j-grw4-6ggj

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-cxxv-5c8r-2cfh

Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-cxxf-6583-j227

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.

CVSS3: 6.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-cxqh-7ch8-jx2g

An issue has been discovered in the GitLab Duo with Amazon Q affecting all versions from 17.8 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A specifically crafted issue could manipulate AI-assisted development features to potentially expose sensitive project data to unauthorized users.

CVSS3: 4.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-cxjq-5xjf-cmp7

An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input.

CVSS3: 8
5%
Низкий
около 3 лет назад
github логотип
GHSA-cxfq-987j-wpfw

Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

CVSS3: 2.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-cxfp-vwqp-ghxf

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn't enabled by default.

CVSS3: 6.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-cxfj-qcv7-fx7w

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cx75-44jc-g7gv

An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу