Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 920

Количество 5 920

github логотип

GHSA-cf8f-2f35-r5wx

9 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to gain CSRF tokens by exploiting improper input validation in repository references combined with redirect handling weaknesses.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-cf86-5cg9-6496

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user could use an unverified email as a public email and commit email by sending a specifically crafted request on user update settings.

EPSS: Низкий
github логотип

GHSA-cf2v-m456-7qjf

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to add unauthorized email addresses to victim accounts through HTML injection in test case titles.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-ccj4-qhw4-4rrm

почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-cc75-w727-3jqw

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their privilege to a maintainer on projects they import

EPSS: Низкий
github логотип

GHSA-c9xg-h9c4-4vv6

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could result in a Denial of Service under specific conditions.

EPSS: Низкий
github логотип

GHSA-c8rf-2f6q-cprc

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.

EPSS: Низкий
github логотип

GHSA-c8m7-c9rp-w2g3

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious user to have their GitHub project imported on another GitLab user account.

EPSS: Низкий
github логотип

GHSA-c89r-pq4x-7rmr

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1. The Jira integration contains a SSRF vulnerability as a result of a bypass of the current protection mechanisms against this type of attack, which would allow sending requests to any resources accessible in the local network by the GitLab server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-c877-4h7h-xvp6

около 4 лет назад

A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to Maintainers

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-c7xg-c3jr-78wp

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific configurations.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-c73g-r4cp-2xmg

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with project membership to enumerate private group members due to missing authorization checks.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-c729-m2g9-m3xv

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. An attacker may upload a crafted CI job artifact zip file in a project that uses dynamic child pipelines and make a sidekiq job allocate a lot of memory. In GitLab instances where Sidekiq is memory-limited, this may cause Denial of Service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-c6r9-q7wr-w7fv

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates by doing a diff with a pre-existing fork.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-c63c-249m-g37m

около 4 лет назад

An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-c5px-g3pm-787c

около 4 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.

EPSS: Низкий
github логотип

GHSA-c5p3-3427-5gqc

около 4 лет назад

The Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-c5g3-c7f9-3hcj

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-c5f7-2j6j-qc5c

около 4 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.6. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-c55j-pgjp-8gv6

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-cf8f-2f35-r5wx

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to gain CSRF tokens by exploiting improper input validation in repository references combined with redirect handling weaknesses.

CVSS3: 3.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-cf86-5cg9-6496

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user could use an unverified email as a public email and commit email by sending a specifically crafted request on user update settings.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-cf2v-m456-7qjf

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to add unauthorized email addresses to victim accounts through HTML injection in test case titles.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-ccj4-qhw4-4rrm

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.

CVSS3: 8.2
0%
Низкий
почти 2 года назад
github логотип
GHSA-cc75-w727-3jqw

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their privilege to a maintainer on projects they import

1%
Низкий
больше 4 лет назад
github логотип
GHSA-c9xg-h9c4-4vv6

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could result in a Denial of Service under specific conditions.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-c8rf-2f6q-cprc

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.

1%
Низкий
около 4 лет назад
github логотип
GHSA-c8m7-c9rp-w2g3

An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious user to have their GitHub project imported on another GitLab user account.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-c89r-pq4x-7rmr

An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1. The Jira integration contains a SSRF vulnerability as a result of a bypass of the current protection mechanisms against this type of attack, which would allow sending requests to any resources accessible in the local network by the GitLab server.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-c877-4h7h-xvp6

A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to Maintainers

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-c7xg-c3jr-78wp

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific configurations.

CVSS3: 8.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-c73g-r4cp-2xmg

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with project membership to enumerate private group members due to missing authorization checks.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-c729-m2g9-m3xv

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. An attacker may upload a crafted CI job artifact zip file in a project that uses dynamic child pipelines and make a sidekiq job allocate a lot of memory. In GitLab instances where Sidekiq is memory-limited, this may cause Denial of Service.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-c6r9-q7wr-w7fv

An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates by doing a diff with a pre-existing fork.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-c63c-249m-g37m

An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-c5px-g3pm-787c

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-c5p3-3427-5gqc

The Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.

CVSS3: 10
2%
Низкий
около 4 лет назад
github логотип
GHSA-c5g3-c7f9-3hcj

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

CVSS3: 4.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-c5f7-2j6j-qc5c

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.6. It has Incorrect Access Control.

1%
Низкий
около 4 лет назад
github логотип
GHSA-c55j-pgjp-8gv6

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу