Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-9pqg-5frc-r6c9

11 месяцев назад

An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-9ppv-xcv2-vhqr

около 3 лет назад

A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to local addresses when configuring a malicious GitLab Runner.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9pcc-mx54-f9hq

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection.

EPSS: Низкий
github логотип

GHSA-9mv9-gw4x-7xw4

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content with nested formatting patterns.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-9mqm-5q47-gj7c

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. It was possible to trigger a DoS attack by uploading a malicious Helm chart.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9mhg-328h-2hfr

около 4 лет назад

Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to a vulnerability which cannot be accessed.

EPSS: Низкий
github логотип

GHSA-9mfx-3c98-hm2f

больше 3 лет назад

A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username.

EPSS: Низкий
github логотип

GHSA-9jvc-93xj-9mfg

около 4 лет назад

An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted docker image to exhaust resources on runner manager

EPSS: Низкий
github логотип

GHSA-9jp8-rx43-82gm

больше 1 года назад

A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-9jcw-6rg2-9fj5

больше 3 лет назад

An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via Epic change descriptions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9j4q-pv73-3355

больше 3 лет назад

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9hww-x8fw-h5f9

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. Membership changes are not reflected in TODO for confidential notes, allowing a former project members to read updates via TODOs.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9hv7-pg48-7596

3 месяца назад

GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker with specific permissions to hijack project runners from other projects.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-9hcx-gvx4-r4rp

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9gf2-jhm2-h977

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for a subgroup member to access the members list of their parent group.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-9fxr-6qgm-fprg

10 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted searches with sensitive keywords to get the count of issues containing the searched term."

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-9fwv-mvpv-qrh4

почти 4 года назад

Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-9cwr-gv28-fqcw

больше 3 лет назад

GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-9cc9-7jvq-f37c

больше 3 лет назад

Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions are: >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-9c64-9pw3-wh7p

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups through GraphQL allowing unauthorised users to perform some actions at the group level.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-9pqg-5frc-r6c9

An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.

CVSS3: 8.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-9ppv-xcv2-vhqr

A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to local addresses when configuring a malicious GitLab Runner.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-9pcc-mx54-f9hq

An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-9mv9-gw4x-7xw4

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content with nested formatting patterns.

CVSS3: 3.5
0%
Низкий
3 месяца назад
github логотип
GHSA-9mqm-5q47-gj7c

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. It was possible to trigger a DoS attack by uploading a malicious Helm chart.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-9mhg-328h-2hfr

Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to a vulnerability which cannot be accessed.

0%
Низкий
около 4 лет назад
github логотип
GHSA-9mfx-3c98-hm2f

A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9jvc-93xj-9mfg

An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted docker image to exhaust resources on runner manager

0%
Низкий
около 4 лет назад
github логотип
GHSA-9jp8-rx43-82gm

A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits.

CVSS3: 2.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-9jcw-6rg2-9fj5

An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via Epic change descriptions.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9j4q-pv73-3355

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9hww-x8fw-h5f9

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. Membership changes are not reflected in TODO for confidential notes, allowing a former project members to read updates via TODOs.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9hv7-pg48-7596

GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker with specific permissions to hijack project runners from other projects.

CVSS3: 8.5
0%
Низкий
3 месяца назад
github логотип
GHSA-9hcx-gvx4-r4rp

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-9gf2-jhm2-h977

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for a subgroup member to access the members list of their parent group.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9fxr-6qgm-fprg

An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted searches with sensitive keywords to get the count of issues containing the searched term."

CVSS3: 6.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-9fwv-mvpv-qrh4

Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

CVSS3: 6.1
10%
Средний
почти 4 года назад
github логотип
GHSA-9cwr-gv28-fqcw

GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.

CVSS3: 5.5
6%
Низкий
больше 3 лет назад
github логотип
GHSA-9cc9-7jvq-f37c

Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions are: >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9c64-9pw3-wh7p

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups through GraphQL allowing unauthorised users to perform some actions at the group level.

CVSS3: 4.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу