Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-962h-g945-9r98

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-95xq-v4m2-fq3r

больше 3 лет назад

GitLab Grit Gem for Ruby contains a flaw allowing arbitrary commands to be executed

EPSS: Низкий
github логотип

GHSA-95hp-m576-m42x

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-94xw-8rg2-4fmc

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-94fv-wxc5-f8vm

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 3 of 3). When a project with visibility more permissive than the target group is imported, it will retain its prior visibility.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-947f-qh3g-pcj5

больше 1 года назад

An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9423-j6rv-rhp5

больше 3 лет назад

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

EPSS: Низкий
github логотип

GHSA-93f4-345x-96mm

больше 3 лет назад

An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-93c3-fhhf-8qpv

почти 3 года назад

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository in "raw" mode, it can be made to render as HTML if viewed under specific circumstances

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-9396-6m54-w269

4 месяца назад

An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintainers can exploit a vulnerability where they can assign custom roles to users with permissions exceeding their own, effectively granting themselves elevated privileges.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-9388-pxcv-qr7p

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-9338-7cq4-hm8v

больше 3 лет назад

In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.

EPSS: Низкий
github логотип

GHSA-92c9-mr48-m5pg

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes

EPSS: Низкий
github логотип

GHSA-923w-9p3x-hmgw

больше 3 лет назад

Jenkins GitLab Plugin missing permission checks

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-9238-gwm5-6mm9

почти 4 года назад

An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-8xwc-6h6p-hh69

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-8xr4-8v2f-pqrx

11 месяцев назад

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8wmm-qgmm-95gm

больше 3 лет назад

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

EPSS: Низкий
github логотип

GHSA-8wjh-279q-q77p

больше 3 лет назад

GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.

EPSS: Низкий
github логотип

GHSA-8wjf-7pjq-2695

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-962h-g945-9r98

An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-95xq-v4m2-fq3r

GitLab Grit Gem for Ruby contains a flaw allowing arbitrary commands to be executed

0%
Низкий
больше 3 лет назад
github логотип
GHSA-95hp-m576-m42x

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-94xw-8rg2-4fmc

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-94fv-wxc5-f8vm

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 3 of 3). When a project with visibility more permissive than the target group is imported, it will retain its prior visibility.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-947f-qh3g-pcj5

An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-9423-j6rv-rhp5

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-93f4-345x-96mm

An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-93c3-fhhf-8qpv

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository in "raw" mode, it can be made to render as HTML if viewed under specific circumstances

CVSS3: 4.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-9396-6m54-w269

An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintainers can exploit a vulnerability where they can assign custom roles to users with permissions exceeding their own, effectively granting themselves elevated privileges.

CVSS3: 3.8
0%
Низкий
4 месяца назад
github логотип
GHSA-9388-pxcv-qr7p

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-9338-7cq4-hm8v

In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-92c9-mr48-m5pg

An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes

0%
Низкий
больше 3 лет назад
github логотип
GHSA-923w-9p3x-hmgw

Jenkins GitLab Plugin missing permission checks

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9238-gwm5-6mm9

An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-8xwc-6h6p-hh69

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-8xr4-8v2f-pqrx

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-8wmm-qgmm-95gm

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-8wjh-279q-q77p

GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-8wjf-7pjq-2695

A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу