Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 918

Количество 5 918

github логотип

GHSA-fvvr-8pf3-2fhf

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Under certain circumstances, CI pipelines could potentially be used in a denial of service attack.

EPSS: Низкий
github логотип

GHSA-fvhv-m54j-g33h

около 4 лет назад

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-fv9w-2hpj-4q5w

почти 4 года назад

A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an authenticated and authorized user to exhaust server resources by importing a malicious project.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-fv26-qm6r-mmq5

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.1, starting from 17.6 prior to 17.6.1, and starting from 17.7 prior to 17.7.1. Under certain conditions, access tokens may have been logged when API requests were made in a specific manner.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-frwx-hm63-346w

около 4 лет назад

GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).

EPSS: Низкий
github логотип

GHSA-frm8-m8r5-fc6j

около 4 лет назад

GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget.

EPSS: Низкий
github логотип

GHSA-fr8h-r296-xggf

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-fr4g-hmc7-w66h

больше 4 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fqvq-p2gc-c297

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to cause denial of service through excessive memory consumption due to improper input validation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-fpgr-mg9w-x2hm

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-fp7j-v353-cf72

около 4 лет назад

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

EPSS: Низкий
github логотип

GHSA-fp74-7pjv-fqcj

около 4 лет назад

An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via request smuggling.

EPSS: Низкий
github логотип

GHSA-fmg9-cqhf-254r

почти 4 года назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-fm8v-3mq9-h889

около 4 лет назад

An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens

EPSS: Низкий
github логотип

GHSA-fm67-vpp9-99gh

около 4 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues

EPSS: Низкий
github логотип

GHSA-fjj2-x466-w3hx

8 месяцев назад

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-fjgv-pw7x-g797

около 4 лет назад

GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.

EPSS: Низкий
github логотип

GHSA-fjc3-h6x3-cpx9

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-fj94-q44p-pf8f

около 4 лет назад

An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method

EPSS: Низкий
github логотип

GHSA-fhrq-2vr4-f65r

около 4 лет назад

Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-fvvr-8pf3-2fhf

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Under certain circumstances, CI pipelines could potentially be used in a denial of service attack.

2%
Низкий
около 4 лет назад
github логотип
GHSA-fvhv-m54j-g33h

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-fv9w-2hpj-4q5w

A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an authenticated and authorized user to exhaust server resources by importing a malicious project.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-fv26-qm6r-mmq5

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.1, starting from 17.6 prior to 17.6.1, and starting from 17.7 prior to 17.7.1. Under certain conditions, access tokens may have been logged when API requests were made in a specific manner.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-frwx-hm63-346w

GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).

1%
Низкий
около 4 лет назад
github логотип
GHSA-frm8-m8r5-fc6j

GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget.

1%
Низкий
около 4 лет назад
github логотип
GHSA-fr8h-r296-xggf

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.

CVSS3: 8.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-fr4g-hmc7-w66h

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-fqvq-p2gc-c297

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to cause denial of service through excessive memory consumption due to improper input validation.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-fpgr-mg9w-x2hm

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVSS3: 9.8
13%
Средний
больше 4 лет назад
github логотип
GHSA-fp7j-v353-cf72

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

1%
Низкий
около 4 лет назад
github логотип
GHSA-fp74-7pjv-fqcj

An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via request smuggling.

1%
Низкий
около 4 лет назад
github логотип
GHSA-fmg9-cqhf-254r

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-fm8v-3mq9-h889

An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens

2%
Низкий
около 4 лет назад
github логотип
GHSA-fm67-vpp9-99gh

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues

1%
Низкий
около 4 лет назад
github логотип
GHSA-fjj2-x466-w3hx

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.

CVSS3: 8.7
1%
Низкий
8 месяцев назад
github логотип
GHSA-fjgv-pw7x-g797

GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.

1%
Низкий
около 4 лет назад
github логотип
GHSA-fjc3-h6x3-cpx9

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-fj94-q44p-pf8f

An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method

1%
Низкий
около 4 лет назад
github логотип
GHSA-fhrq-2vr4-f65r

Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics

1%
Низкий
около 4 лет назад

Уязвимостей на страницу