Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 920

Количество 5 920

github логотип

GHSA-f8q5-vhrp-8mfc

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 8.10 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Under specific circumstances, a user importing a project 'from export' could access and read unrelated files via uploading a specially crafted file. This was due to a bug in `tar`, fixed in [`tar-1.35`](https://lists.gnu.org/archive/html/info-gnu/2023-07/msg00005.html).

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-f8f8-vpg5-qg2x

почти 2 года назад

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-f82f-w24c-j3ww

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-f7qj-p2x6-5jf3

около 4 лет назад

A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthorized user can create and delete deploy tokens.

EPSS: Низкий
github логотип

GHSA-f7gw-576r-4q7w

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to leak a webhook secret token by changing the webhook URL to an endpoint that allows them to capture request headers.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-f7c4-9mmj-8w4v

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-f73r-7g7h-494m

больше 1 года назад

An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-f6r3-7fw8-rpcg

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-f6gp-6x43-895w

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

EPSS: Низкий
github логотип

GHSA-f655-xhvm-cwp4

около 4 лет назад

Cross-site Scripting in Jenkins GitLab Plugin

CVSS3: 8
EPSS: Высокий
github логотип

GHSA-f5vg-g8qw-8p89

почти 4 года назад

An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-f5r5-77wf-xx6h

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-f4ff-rc49-g8hc

больше 3 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-f48g-wqmg-9r45

почти 2 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause catastrophic backtracking while parsing results from Elasticsearch.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-f435-r8xf-rc9w

около 4 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature.

EPSS: Низкий
github логотип

GHSA-f3wg-5hg2-8j39

около 3 лет назад

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions, an attacker may be able to map a private email of a GitLab user to their GitLab account on an instance.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-f3mf-g3hh-m9vw

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled.

EPSS: Низкий
github логотип

GHSA-f3jj-mgwg-pc9w

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information Exposure Through an Error Message.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-f3gg-585w-gjj2

2 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to access sensitive deployment data on projects due to improper authorization checks.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-f3g5-424c-vfvp

около 4 лет назад

Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner is calling from outside the allowed IP range

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-f8q5-vhrp-8mfc

An issue has been discovered in GitLab affecting all versions starting from 8.10 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Under specific circumstances, a user importing a project 'from export' could access and read unrelated files via uploading a specially crafted file. This was due to a bug in `tar`, fixed in [`tar-1.35`](https://lists.gnu.org/archive/html/info-gnu/2023-07/msg00005.html).

CVSS3: 6.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-f8f8-vpg5-qg2x

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVSS3: 4.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-f82f-w24c-j3ww

An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-f7qj-p2x6-5jf3

A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthorized user can create and delete deploy tokens.

1%
Низкий
около 4 лет назад
github логотип
GHSA-f7gw-576r-4q7w

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to leak a webhook secret token by changing the webhook URL to an endpoint that allows them to capture request headers.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-f7c4-9mmj-8w4v

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.

CVSS3: 6.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-f73r-7g7h-494m

An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way.

CVSS3: 4.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-f6r3-7fw8-rpcg

An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-f6gp-6x43-895w

An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

1%
Низкий
около 4 лет назад
github логотип
GHSA-f655-xhvm-cwp4

Cross-site Scripting in Jenkins GitLab Plugin

CVSS3: 8
73%
Высокий
около 4 лет назад
github логотип
GHSA-f5vg-g8qw-8p89

An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-f5r5-77wf-xx6h

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.

CVSS3: 8.2
1%
Низкий
больше 1 года назад
github логотип
GHSA-f4ff-rc49-g8hc

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-f48g-wqmg-9r45

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause catastrophic backtracking while parsing results from Elasticsearch.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-f435-r8xf-rc9w

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature.

1%
Низкий
около 4 лет назад
github логотип
GHSA-f3wg-5hg2-8j39

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions, an attacker may be able to map a private email of a GitLab user to their GitLab account on an instance.

CVSS3: 3.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-f3mf-g3hh-m9vw

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled.

2%
Низкий
около 4 лет назад
github логотип
GHSA-f3jj-mgwg-pc9w

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information Exposure Through an Error Message.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-f3gg-585w-gjj2

GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to access sensitive deployment data on projects due to improper authorization checks.

CVSS3: 4.3
0%
Низкий
2 месяца назад
github логотип
GHSA-f3g5-424c-vfvp

Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner is calling from outside the allowed IP range

CVSS3: 6.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу