Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 918

Количество 5 918

github логотип

GHSA-fh9c-h28h-pf65

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-fh7h-m5x3-9v4g

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previously removed malicious maintainer or owner of the child group can still gain access to the group via SSO or a SCIM token to perform actions on the group.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-fh73-gxwx-h999

около 4 лет назад

GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.

EPSS: Низкий
github логотип

GHSA-fh2j-rw8g-c7f3

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-fgvw-2v52-jhfv

почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-ffcr-rwf9-9f8f

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-ffch-rw3v-4mvx

4 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to cause denial of service to the GitLab instance due to improper input validation in GraphQL queries.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-ff7f-54gm-r4p6

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

EPSS: Низкий
github логотип

GHSA-ff73-cwc3-6v5j

около 4 лет назад

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

EPSS: Низкий
github логотип

GHSA-ff57-593p-9ffx

около 4 лет назад

An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the GFM markdown API.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-fcwc-pv7g-5mr8

около 4 лет назад

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-fcmm-jq9f-cc5p

около 4 лет назад

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fccc-r92h-5q24

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. It was possible for authenticated users to access arbitrary compliance frameworks, leading to unauthorized data disclosure.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fcc5-x3g2-xc22

около 4 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-fc6w-qm7g-jfwh

около 1 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in the context of another user's session, due to improper sanitization of user-supplied input.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-fc33-2q9r-qr2m

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

EPSS: Высокий
github логотип

GHSA-f9v8-6c5p-2whh

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-f9f9-4r63-4qcc

почти 4 года назад

Non-constant time webhook token comparison in Jenkins GitLab Plugin

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-f938-px45-qqjc

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. Private project paths can be disclosed to unauthorized users via system notes when an Issue is closed via a Merge Request and later moved to a public project

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-f8ww-p9xj-cm59

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in how the application parses user agents.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-fh9c-h28h-pf65

An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-fh7h-m5x3-9v4g

An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previously removed malicious maintainer or owner of the child group can still gain access to the group via SSO or a SCIM token to perform actions on the group.

CVSS3: 7.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-fh73-gxwx-h999

GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.

1%
Низкий
около 4 лет назад
github логотип
GHSA-fh2j-rw8g-c7f3

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 8.2
1%
Низкий
почти 2 года назад
github логотип
GHSA-fgvw-2v52-jhfv

An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-ffcr-rwf9-9f8f

An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-ffch-rw3v-4mvx

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to cause denial of service to the GitLab instance due to improper input validation in GraphQL queries.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-ff7f-54gm-r4p6

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

1%
Низкий
около 4 лет назад
github логотип
GHSA-ff73-cwc3-6v5j

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

2%
Низкий
около 4 лет назад
github логотип
GHSA-ff57-593p-9ffx

An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the GFM markdown API.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-fcwc-pv7g-5mr8

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-fcmm-jq9f-cc5p

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-fccc-r92h-5q24

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. It was possible for authenticated users to access arbitrary compliance frameworks, leading to unauthorized data disclosure.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-fcc5-x3g2-xc22

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-fc6w-qm7g-jfwh

GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in the context of another user's session, due to improper sanitization of user-supplied input.

CVSS3: 8.7
0%
Низкий
около 1 месяца назад
github логотип
GHSA-fc33-2q9r-qr2m

An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

72%
Высокий
около 4 лет назад
github логотип
GHSA-f9v8-6c5p-2whh

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-f9f9-4r63-4qcc

Non-constant time webhook token comparison in Jenkins GitLab Plugin

CVSS3: 3.7
1%
Низкий
почти 4 года назад
github логотип
GHSA-f938-px45-qqjc

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. Private project paths can be disclosed to unauthorized users via system notes when an Issue is closed via a Merge Request and later moved to a public project

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-f8ww-p9xj-cm59

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in how the application parses user agents.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу