Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 920

Количество 5 920

github логотип

GHSA-f3cp-f6ph-xxhj

около 4 лет назад

In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s password via the change password function. There is a rate limit in place, but the attack may still be conducted by stealing the session id from the physical compromise of the account and splitting the attack over several IP addresses and passing in the compromised session value from these various locations.

EPSS: Низкий
github логотип

GHSA-f2h5-25cx-h2f5

около 4 лет назад

The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-f28j-grw4-6ggj

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-cxxv-5c8r-2cfh

больше 4 лет назад

Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-cxxf-6583-j227

12 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-cxqh-7ch8-jx2g

больше 1 года назад

An issue has been discovered in the GitLab Duo with Amazon Q affecting all versions from 17.8 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A specifically crafted issue could manipulate AI-assisted development features to potentially expose sensitive project data to unauthorized users.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-cxjq-5xjf-cmp7

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-cxfq-987j-wpfw

больше 4 лет назад

Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-cxfp-vwqp-ghxf

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn't enabled by default.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-cxfj-qcv7-fx7w

около 4 лет назад

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

EPSS: Низкий
github логотип

GHSA-cx75-44jc-g7gv

около 4 лет назад

An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.

EPSS: Низкий
github логотип

GHSA-cx4g-hr74-m89m

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsing middleware.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cwjh-rrw3-f8rp

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2. This issue allows an attacker to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-cw76-xvhc-pwcw

около 4 лет назад

An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node.

EPSS: Низкий
github логотип

GHSA-cvvf-6v6p-vxjx

около 4 лет назад

GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.

EPSS: Низкий
github логотип

GHSA-cvqc-8rrv-whf2

около 4 лет назад

A Stored XSS in merge request creation page in Gitlab EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-cv6r-jfw8-2rmq

около 4 лет назад

Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-cv3h-4g8c-4vw6

3 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-crr3-cvh5-8wfr

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-cr8m-4w78-jxp2

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information Exposure Through Browser Caching.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-f3cp-f6ph-xxhj

In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s password via the change password function. There is a rate limit in place, but the attack may still be conducted by stealing the session id from the physical compromise of the account and splitting the attack over several IP addresses and passing in the compromised session value from these various locations.

0%
Низкий
около 4 лет назад
github логотип
GHSA-f2h5-25cx-h2f5

The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-f28j-grw4-6ggj

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-cxxv-5c8r-2cfh

Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-cxxf-6583-j227

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.

CVSS3: 6.7
0%
Низкий
12 месяцев назад
github логотип
GHSA-cxqh-7ch8-jx2g

An issue has been discovered in the GitLab Duo with Amazon Q affecting all versions from 17.8 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A specifically crafted issue could manipulate AI-assisted development features to potentially expose sensitive project data to unauthorized users.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-cxjq-5xjf-cmp7

An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input.

CVSS3: 8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-cxfq-987j-wpfw

Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

CVSS3: 2.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-cxfp-vwqp-ghxf

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn't enabled by default.

CVSS3: 6.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-cxfj-qcv7-fx7w

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

1%
Низкий
около 4 лет назад
github логотип
GHSA-cx75-44jc-g7gv

An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.

1%
Низкий
около 4 лет назад
github логотип
GHSA-cx4g-hr74-m89m

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsing middleware.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-cwjh-rrw3-f8rp

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2. This issue allows an attacker to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks.

CVSS3: 3.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-cw76-xvhc-pwcw

An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node.

1%
Низкий
около 4 лет назад
github логотип
GHSA-cvvf-6v6p-vxjx

GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.

2%
Низкий
около 4 лет назад
github логотип
GHSA-cvqc-8rrv-whf2

A Stored XSS in merge request creation page in Gitlab EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-cv6r-jfw8-2rmq

Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution.

CVSS3: 8.8
5%
Низкий
около 4 лет назад
github логотип
GHSA-cv3h-4g8c-4vw6

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization.

CVSS3: 8.7
0%
Низкий
3 месяца назад
github логотип
GHSA-crr3-cvh5-8wfr

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-cr8m-4w78-jxp2

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information Exposure Through Browser Caching.

CVSS3: 6.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу