Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 4 556

Количество 4 556

github логотип

GHSA-wf4m-rq68-3mfc

больше 2 лет назад

Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wf25-2f67-3rmc

около 3 лет назад

Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted commit to a wiki

EPSS: Низкий
github логотип

GHSA-wccp-g34r-cx74

больше 2 лет назад

An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-wc5c-7jg2-cprf

почти 2 года назад

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-w9qv-xhc6-m43c

12 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-w843-hcjg-c7v5

больше 2 лет назад

An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a malicious users to set emojis on internal notes they don't have access to.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-w7x8-xmgq-vf54

около 3 лет назад

GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions.

EPSS: Низкий
github логотип

GHSA-w7pv-hcjh-p9w4

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML in an email address field.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-w7m8-v47c-mr4h

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A user's primary email may be disclosed to an attacker through group member events webhooks.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-w7hh-546g-p758

около 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions.

EPSS: Низкий
github логотип

GHSA-w7ff-cwfc-582x

около 3 лет назад

An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.

EPSS: Низкий
github логотип

GHSA-w772-f4fj-g5xq

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4. It has Insecure Permissions.

EPSS: Низкий
github логотип

GHSA-w75c-wmw7-rfpv

около 3 лет назад

An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-w6pv-c757-6rgr

около 3 лет назад

apollo_upload_server has Denial of Service vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w673-w4h7-244x

около 3 лет назад

Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9

EPSS: Низкий
github логотип

GHSA-w5qp-8fgp-fmjj

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. GitLab Pages contains a directory traversal vulnerability that could lead to remote command execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-w555-m56g-r558

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows Information Exposure via a Gitlab Prometheus integration.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w4wr-jxpf-c7j5

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the merge request JSON endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-w4fh-mw73-5c5w

больше 2 лет назад

A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w3fw-23jp-3855

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-wf4m-rq68-3mfc

Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-wf25-2f67-3rmc

Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted commit to a wiki

0%
Низкий
около 3 лет назад
github логотип
GHSA-wccp-g34r-cx74

An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-wc5c-7jg2-cprf

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API.

CVSS3: 2.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-w9qv-xhc6-m43c

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.

CVSS3: 6.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-w843-hcjg-c7v5

An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a malicious users to set emojis on internal notes they don't have access to.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-w7x8-xmgq-vf54

GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions.

0%
Низкий
около 3 лет назад
github логотип
GHSA-w7pv-hcjh-p9w4

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML in an email address field.

CVSS3: 4.1
1%
Низкий
почти 2 года назад
github логотип
GHSA-w7m8-v47c-mr4h

An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A user's primary email may be disclosed to an attacker through group member events webhooks.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-w7hh-546g-p758

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions.

0%
Низкий
около 3 лет назад
github логотип
GHSA-w7ff-cwfc-582x

An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.

0%
Низкий
около 3 лет назад
github логотип
GHSA-w772-f4fj-g5xq

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4. It has Insecure Permissions.

0%
Низкий
около 3 лет назад
github логотип
GHSA-w75c-wmw7-rfpv

An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 3.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-w6pv-c757-6rgr

apollo_upload_server has Denial of Service vulnerability

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-w673-w4h7-244x

Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9

0%
Низкий
около 3 лет назад
github логотип
GHSA-w5qp-8fgp-fmjj

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. GitLab Pages contains a directory traversal vulnerability that could lead to remote command execution.

CVSS3: 8.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-w555-m56g-r558

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows Information Exposure via a Gitlab Prometheus integration.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-w4wr-jxpf-c7j5

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the merge request JSON endpoint.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-w4fh-mw73-5c5w

A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-w3fw-23jp-3855

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.

CVSS3: 6.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу