Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-wmcm-x8vj-qqp7

почти 4 года назад

GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-wm64-hhrx-w2h7

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter using rouge can block for a long time in Sidekiq jobs without any timeout.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wjpf-p2m9-5wmv

почти 4 года назад

In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-wjh7-hp74-8r7h

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 2.1.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. A lack of input validation in HTTP responses could allow an authenticated user to cause denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-wjcq-cqhf-f7rm

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-wj4p-jhrc-wr8q

16 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially crafted JSON payloads in the protected branches API.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-whxf-7mv4-g5wm

почти 4 года назад

An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. When group SAML SSO is configured, the SCIM feature (available only on Premium+ subscriptions) may allow any owner of a Premium group to invite arbitrary users through their username and email, then change those users' email addresses via SCIM to an attacker controlled email address and thus - in the absence of 2FA - take over those accounts. It is also possible for the attacker to change the display name and username of the targeted account.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-wh94-79gr-cv69

почти 4 года назад

A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added.

EPSS: Низкий
github логотип

GHSA-wh39-vq4j-xpj4

почти 4 года назад

GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-wgh9-p42c-pq7h

почти 4 года назад

Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-wggh-9jhq-9h7x

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the GraphQL API.

EPSS: Низкий
github логотип

GHSA-wg76-c5w5-h7xg

почти 4 года назад

Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.

EPSS: Низкий
github логотип

GHSA-wg27-v6fh-mh3j

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could potentially lead a victim to download malicious code.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-wfj3-6j6g-rpwx

почти 4 года назад

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

EPSS: Низкий
github логотип

GHSA-wf4m-rq68-3mfc

около 3 лет назад

Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wf25-2f67-3rmc

почти 4 года назад

Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted commit to a wiki

EPSS: Низкий
github логотип

GHSA-wcpq-3gmh-2fh6

9 месяцев назад

An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-wccp-g34r-cx74

больше 3 лет назад

An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-wc5c-7jg2-cprf

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-w9qv-xhc6-m43c

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-wmcm-x8vj-qqp7

GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component.

CVSS3: 9.8
40%
Средний
почти 4 года назад
github логотип
GHSA-wm64-hhrx-w2h7

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter using rouge can block for a long time in Sidekiq jobs without any timeout.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-wjpf-p2m9-5wmv

In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-wjh7-hp74-8r7h

An issue has been discovered in GitLab CE/EE affecting all versions from 2.1.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. A lack of input validation in HTTP responses could allow an authenticated user to cause denial of service.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-wjcq-cqhf-f7rm

An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.

CVSS3: 8.7
0%
Низкий
10 месяцев назад
github логотип
GHSA-wj4p-jhrc-wr8q

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially crafted JSON payloads in the protected branches API.

CVSS3: 7.5
0%
Низкий
16 дней назад
github логотип
GHSA-whxf-7mv4-g5wm

An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. When group SAML SSO is configured, the SCIM feature (available only on Premium+ subscriptions) may allow any owner of a Premium group to invite arbitrary users through their username and email, then change those users' email addresses via SCIM to an attacker controlled email address and thus - in the absence of 2FA - take over those accounts. It is also possible for the attacker to change the display name and username of the targeted account.

CVSS3: 8.8
10%
Средний
почти 4 года назад
github логотип
GHSA-wh94-79gr-cv69

A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added.

0%
Низкий
почти 4 года назад
github логотип
GHSA-wh39-vq4j-xpj4

GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.

0%
Низкий
почти 4 года назад
github логотип
GHSA-wgh9-p42c-pq7h

Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-wggh-9jhq-9h7x

An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the GraphQL API.

0%
Низкий
около 4 лет назад
github логотип
GHSA-wg76-c5w5-h7xg

Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.

0%
Низкий
почти 4 года назад
github логотип
GHSA-wg27-v6fh-mh3j

An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could potentially lead a victim to download malicious code.

CVSS3: 4.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-wfj3-6j6g-rpwx

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

2%
Низкий
почти 4 года назад
github логотип
GHSA-wf4m-rq68-3mfc

Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-wf25-2f67-3rmc

Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted commit to a wiki

0%
Низкий
почти 4 года назад
github логотип
GHSA-wcpq-3gmh-2fh6

An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials.

CVSS3: 4.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-wccp-g34r-cx74

An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-wc5c-7jg2-cprf

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API.

CVSS3: 2.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-w9qv-xhc6-m43c

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.

CVSS3: 6.8
0%
Низкий
почти 2 года назад

Уязвимостей на страницу