Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-9xx7-rp3v-8694

почти 2 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. It is possible for an attacker to cause a denial of service using a crafted wiki page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-9xww-4cjx-6w55

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9xv2-8g99-6925

больше 4 лет назад

An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members

EPSS: Низкий
github логотип

GHSA-9xhf-gx34-9q2g

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-9x8h-2288-5g98

больше 1 года назад

ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of service via Regex backtracking.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9x26-6h4w-rqx8

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for email invited members to join a project even after the Group Owner has enabled the setting to prevent members from being added to projects in a group, if the invite was sent before the setting was enabled.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-9wrx-mw8f-hx7p

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9wg9-668g-hc95

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressions in GitLab Markdown can exhaust client resources.

EPSS: Низкий
github логотип

GHSA-9wfx-xq2g-33pv

больше 3 лет назад

An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9w7f-mwxm-3g85

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a large `glm_source` parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9w35-73xp-56pr

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline details page allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9vrq-hh79-6v9m

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-9vpf-9m6p-h2rr

почти 4 года назад

An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-9vfc-hfq9-h2v4

почти 4 года назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 10.8 through 12.6.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-9v59-ffhf-ccr8

почти 4 года назад

An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with

EPSS: Низкий
github логотип

GHSA-9v48-rxrr-h9qh

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improved authentication and session management.

EPSS: Низкий
github логотип

GHSA-9rx5-594g-qxq8

почти 4 года назад

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

EPSS: Низкий
github логотип

GHSA-9r89-5vm4-vcr8

почти 4 года назад

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-9r4p-g7c7-2c4r

почти 2 года назад

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-9r3x-jfv9-5w6c

почти 4 года назад

GitLab through 12.7.2 allows XSS.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-9xx7-rp3v-8694

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. It is possible for an attacker to cause a denial of service using a crafted wiki page.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-9xww-4cjx-6w55

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-9xv2-8g99-6925

An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members

0%
Низкий
больше 4 лет назад
github логотип
GHSA-9xhf-gx34-9q2g

An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization

CVSS3: 6.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-9x8h-2288-5g98

ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of service via Regex backtracking.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-9x26-6h4w-rqx8

An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for email invited members to join a project even after the Group Owner has enabled the setting to prevent members from being added to projects in a group, if the invite was sent before the setting was enabled.

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9wrx-mw8f-hx7p

An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-9wg9-668g-hc95

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressions in GitLab Markdown can exhaust client resources.

0%
Низкий
почти 4 года назад
github логотип
GHSA-9wfx-xq2g-33pv

An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9w7f-mwxm-3g85

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a large `glm_source` parameter.

CVSS3: 7.5
5%
Низкий
больше 1 года назад
github логотип
GHSA-9w35-73xp-56pr

An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline details page allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-9vrq-hh79-6v9m

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.

CVSS3: 4.9
0%
Низкий
10 месяцев назад
github логотип
GHSA-9vpf-9m6p-h2rr

An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-9vfc-hfq9-h2v4

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 10.8 through 12.6.1. It has Incorrect Access Control.

0%
Низкий
почти 4 года назад
github логотип
GHSA-9v59-ffhf-ccr8

An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with

0%
Низкий
почти 4 года назад
github логотип
GHSA-9v48-rxrr-h9qh

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improved authentication and session management.

0%
Низкий
почти 4 года назад
github логотип
GHSA-9rx5-594g-qxq8

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

0%
Низкий
почти 4 года назад
github логотип
GHSA-9r89-5vm4-vcr8

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-9r4p-g7c7-2c4r

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

CVSS3: 8
7%
Низкий
почти 2 года назад
github логотип
GHSA-9r3x-jfv9-5w6c

GitLab through 12.7.2 allows XSS.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу