Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-c5px-g3pm-787c

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.

EPSS: Низкий
github логотип

GHSA-c5p3-3427-5gqc

больше 3 лет назад

The Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-c5g3-c7f9-3hcj

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-c5f7-2j6j-qc5c

больше 3 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.6. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-c55j-pgjp-8gv6

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-c4p9-w9gc-7j5g

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not invalidating project invitation link upon removing a user from a project.

EPSS: Низкий
github логотип

GHSA-c482-98mv-jjm6

больше 3 лет назад

An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private projects.

EPSS: Низкий
github логотип

GHSA-c459-gw6c-ch4j

больше 3 лет назад

GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-c3wj-324v-hrrc

около 3 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to use GitLab Flavored Markdown (GFM) references in a Jira issue to disclose the names of resources they don't have access to.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-c3rv-jv45-94rx

больше 3 лет назад

In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project. Under specialized conditions, this may lead to information disclosure if the project is imported from an untrusted source.

EPSS: Низкий
github логотип

GHSA-c3qm-r5gp-mgpm

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible to disclose the branch names when attacker has a fork of a project that was switched to private.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-c3ph-4hj5-r598

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, with the processing logic for generating link in dependency files can lead to a regular expression DoS attack on the server

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-c3j4-p4mf-9hj3

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-c3hq-3p4c-ch2w

около 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects' release descriptions via an atom endpoint when release access on the public was set to only project members.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-c3cp-7jp9-c872

2 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user with specific permissions to cause a denial of service condition through HTTP response processing.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-c354-rm47-933j

больше 3 лет назад

An Information Exposure issue (issue 2 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. During the OAuth authentication process, the application attempts to validate a parameter in an insecure way, potentially exposing data.

EPSS: Низкий
github логотип

GHSA-c2wf-8j59-jjhc

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.5 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. A crafted wildcard filter in FileFinder may lead to a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-c246-wwgq-rr54

больше 3 лет назад

An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9xx7-rp3v-8694

больше 1 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. It is possible for an attacker to cause a denial of service using a crafted wiki page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-9xww-4cjx-6w55

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-c5px-g3pm-787c

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-c5p3-3427-5gqc

The Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.

CVSS3: 10
0%
Низкий
больше 3 лет назад
github логотип
GHSA-c5g3-c7f9-3hcj

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

CVSS3: 4.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-c5f7-2j6j-qc5c

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.6. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-c55j-pgjp-8gv6

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-c4p9-w9gc-7j5g

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not invalidating project invitation link upon removing a user from a project.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-c482-98mv-jjm6

An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private projects.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-c459-gw6c-ch4j

GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-c3wj-324v-hrrc

An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to use GitLab Flavored Markdown (GFM) references in a Jira issue to disclose the names of resources they don't have access to.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-c3rv-jv45-94rx

In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project. Under specialized conditions, this may lead to information disclosure if the project is imported from an untrusted source.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-c3qm-r5gp-mgpm

An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible to disclose the branch names when attacker has a fork of a project that was switched to private.

CVSS3: 3.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-c3ph-4hj5-r598

An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, with the processing logic for generating link in dependency files can lead to a regular expression DoS attack on the server

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-c3j4-p4mf-9hj3

An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-c3hq-3p4c-ch2w

An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects' release descriptions via an atom endpoint when release access on the public was set to only project members.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-c3cp-7jp9-c872

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user with specific permissions to cause a denial of service condition through HTTP response processing.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-c354-rm47-933j

An Information Exposure issue (issue 2 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. During the OAuth authentication process, the application attempts to validate a parameter in an insecure way, potentially exposing data.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-c2wf-8j59-jjhc

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.5 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. A crafted wildcard filter in FileFinder may lead to a denial of service.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-c246-wwgq-rr54

An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-9xx7-rp3v-8694

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. It is possible for an attacker to cause a denial of service using a crafted wiki page.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-9xww-4cjx-6w55

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

CVSS3: 5.3
0%
Низкий
около 1 года назад

Уязвимостей на страницу