Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-9xv2-8g99-6925

около 4 лет назад

An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members

EPSS: Низкий
github логотип

GHSA-9xhf-gx34-9q2g

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-9x8h-2288-5g98

больше 1 года назад

ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of service via Regex backtracking.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9x26-6h4w-rqx8

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for email invited members to join a project even after the Group Owner has enabled the setting to prevent members from being added to projects in a group, if the invite was sent before the setting was enabled.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-9wrx-mw8f-hx7p

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9wg9-668g-hc95

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressions in GitLab Markdown can exhaust client resources.

EPSS: Низкий
github логотип

GHSA-9wfx-xq2g-33pv

больше 3 лет назад

An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9w7f-mwxm-3g85

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a large `glm_source` parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9w35-73xp-56pr

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline details page allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9vrq-hh79-6v9m

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-9vpf-9m6p-h2rr

больше 3 лет назад

An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-9vfc-hfq9-h2v4

больше 3 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 10.8 through 12.6.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-9v59-ffhf-ccr8

больше 3 лет назад

An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with

EPSS: Низкий
github логотип

GHSA-9v48-rxrr-h9qh

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improved authentication and session management.

EPSS: Низкий
github логотип

GHSA-9rx5-594g-qxq8

больше 3 лет назад

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

EPSS: Низкий
github логотип

GHSA-9r89-5vm4-vcr8

больше 3 лет назад

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-9r4p-g7c7-2c4r

больше 1 года назад

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-9r3x-jfv9-5w6c

больше 3 лет назад

GitLab through 12.7.2 allows XSS.

EPSS: Низкий
github логотип

GHSA-9q79-pqhq-v25q

больше 3 лет назад

GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.

EPSS: Низкий
github логотип

GHSA-9q2c-4gv2-vv76

больше 3 лет назад

An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-9xv2-8g99-6925

An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members

0%
Низкий
около 4 лет назад
github логотип
GHSA-9xhf-gx34-9q2g

An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-9x8h-2288-5g98

ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of service via Regex backtracking.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-9x26-6h4w-rqx8

An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for email invited members to join a project even after the Group Owner has enabled the setting to prevent members from being added to projects in a group, if the invite was sent before the setting was enabled.

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9wrx-mw8f-hx7p

An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9wg9-668g-hc95

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressions in GitLab Markdown can exhaust client resources.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9wfx-xq2g-33pv

An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9w7f-mwxm-3g85

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a large `glm_source` parameter.

CVSS3: 7.5
6%
Низкий
больше 1 года назад
github логотип
GHSA-9w35-73xp-56pr

An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline details page allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9vrq-hh79-6v9m

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.

CVSS3: 4.9
0%
Низкий
9 месяцев назад
github логотип
GHSA-9vpf-9m6p-h2rr

An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9vfc-hfq9-h2v4

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 10.8 through 12.6.1. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9v59-ffhf-ccr8

An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9v48-rxrr-h9qh

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improved authentication and session management.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9rx5-594g-qxq8

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9r89-5vm4-vcr8

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9r4p-g7c7-2c4r

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

CVSS3: 8
9%
Низкий
больше 1 года назад
github логотип
GHSA-9r3x-jfv9-5w6c

GitLab through 12.7.2 allows XSS.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9q79-pqhq-v25q

GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9q2c-4gv2-vv76

An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу