Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 920

Количество 5 920

github логотип

GHSA-cr3m-m96g-29v4

около 4 лет назад

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Insufficient permission check allows attacker with developer role to perform various deletions.

EPSS: Низкий
github логотип

GHSA-cqvh-4wv3-g3cj

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-cqj2-v4jv-jmhc

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by changing the configured URL in the Sentry error tracking settings page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-cqcc-25cv-67xr

больше 4 лет назад

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-cpx5-2q84-prc5

8 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to leak sensitive information from specifically crafted merge request titles.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-cpvr-6632-w329

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-cpg4-gv23-mpmj

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. Users were capable of linking CI/CD jobs of private projects which they are not a member of.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-cmg3-7mvj-rgrr

около 4 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.3 through 12.6.1. It allows Denial of Service.

EPSS: Низкий
github логотип

GHSA-cjjr-h37f-5xw7

около 3 лет назад

An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-cjf2-62xp-p6mj

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Access tokens may have been logged when a query was made to a specific endpoint.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-chxc-x49q-7m83

почти 3 года назад

An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-chvg-47qc-prxj

около 4 лет назад

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-chjh-944f-687f

около 2 лет назад

Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-ch28-63rq-r3fw

около 4 лет назад

GitLab 12.2 through 12.8.1 allows Denial of Service. A denial of service vulnerability impacting the designs for public issues was discovered.

EPSS: Низкий
github логотип

GHSA-cgm9-25c8-vhvr

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to XSS.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-cfwx-6jvv-mvcm

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 4 of 5).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-cfp6-wq22-gv3m

около 4 лет назад

A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the gitlab-runner process crash by sending malformed queries, resulting in a denial of service.

EPSS: Низкий
github логотип

GHSA-cfp2-8mw9-wg68

около 4 лет назад

An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-cfhj-wmq5-2vrv

около 4 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Omniauth endpoint allowed a malicious user to submit content to be displayed back to the user within error messages.

EPSS: Низкий
github логотип

GHSA-cf9g-jhqf-gm5j

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker can clone a repository from a public project, from a disallowed IP, even after the top-level group has enabled IP restrictions on the group.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-cr3m-m96g-29v4

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Insufficient permission check allows attacker with developer role to perform various deletions.

1%
Низкий
около 4 лет назад
github логотип
GHSA-cqvh-4wv3-g3cj

An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input.

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-cqj2-v4jv-jmhc

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by changing the configured URL in the Sentry error tracking settings page.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-cqcc-25cv-67xr

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-cpx5-2q84-prc5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to leak sensitive information from specifically crafted merge request titles.

CVSS3: 3.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-cpvr-6632-w329

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-cpg4-gv23-mpmj

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. Users were capable of linking CI/CD jobs of private projects which they are not a member of.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-cmg3-7mvj-rgrr

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.3 through 12.6.1. It allows Denial of Service.

1%
Низкий
около 4 лет назад
github логотип
GHSA-cjjr-h37f-5xw7

An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.

CVSS3: 5
1%
Низкий
около 3 лет назад
github логотип
GHSA-cjf2-62xp-p6mj

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Access tokens may have been logged when a query was made to a specific endpoint.

CVSS3: 4.9
1%
Низкий
около 3 лет назад
github логотип
GHSA-chxc-x49q-7m83

An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.

CVSS3: 8.2
1%
Низкий
почти 3 года назад
github логотип
GHSA-chvg-47qc-prxj

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-chjh-944f-687f

Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-ch28-63rq-r3fw

GitLab 12.2 through 12.8.1 allows Denial of Service. A denial of service vulnerability impacting the designs for public issues was discovered.

1%
Низкий
около 4 лет назад
github логотип
GHSA-cgm9-25c8-vhvr

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to XSS.

CVSS3: 8.7
0%
Низкий
около 1 года назад
github логотип
GHSA-cfwx-6jvv-mvcm

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 4 of 5).

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-cfp6-wq22-gv3m

A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the gitlab-runner process crash by sending malformed queries, resulting in a denial of service.

2%
Низкий
около 4 лет назад
github логотип
GHSA-cfp2-8mw9-wg68

An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-cfhj-wmq5-2vrv

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Omniauth endpoint allowed a malicious user to submit content to be displayed back to the user within error messages.

1%
Низкий
около 4 лет назад
github логотип
GHSA-cf9g-jhqf-gm5j

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker can clone a repository from a public project, from a disallowed IP, even after the top-level group has enabled IP restrictions on the group.

CVSS3: 5.9
0%
Низкий
около 3 лет назад

Уязвимостей на страницу