Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-96gj-7pcm-7895

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for groups that restrict membership by email domain.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-96cq-cj7w-27g2

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-9672-4fh3-mcfg

больше 3 лет назад

Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allowed Developers to view the project's Audit Events and Developers or Maintainers to view the group's Audit Events. These should have been restricted to Project Maintainers, Group Owners, and above.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-962h-g945-9r98

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-95xq-v4m2-fq3r

почти 4 года назад

GitLab Grit Gem for Ruby contains a flaw allowing arbitrary commands to be executed

EPSS: Низкий
github логотип

GHSA-95p8-ccjw-3g7f

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an authenticated developer to hide specially crafted file changes from the WebUI.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-95hp-m576-m42x

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-94xw-8rg2-4fmc

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-94fv-wxc5-f8vm

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 3 of 3). When a project with visibility more permissive than the target group is imported, it will retain its prior visibility.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-947f-qh3g-pcj5

больше 1 года назад

An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9423-j6rv-rhp5

почти 4 года назад

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

EPSS: Низкий
github логотип

GHSA-93f4-345x-96mm

почти 4 года назад

An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-93c3-fhhf-8qpv

почти 3 года назад

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository in "raw" mode, it can be made to render as HTML if viewed under specific circumstances

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-9396-6m54-w269

6 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintainers can exploit a vulnerability where they can assign custom roles to users with permissions exceeding their own, effectively granting themselves elevated privileges.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-9388-pxcv-qr7p

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-9338-7cq4-hm8v

почти 4 года назад

In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.

EPSS: Низкий
github логотип

GHSA-92c9-mr48-m5pg

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes

EPSS: Низкий
github логотип

GHSA-923w-9p3x-hmgw

почти 4 года назад

Jenkins GitLab Plugin missing permission checks

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-9238-gwm5-6mm9

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-8xwc-6h6p-hh69

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-96gj-7pcm-7895

An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for groups that restrict membership by email domain.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-96cq-cj7w-27g2

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-9672-4fh3-mcfg

Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allowed Developers to view the project's Audit Events and Developers or Maintainers to view the group's Audit Events. These should have been restricted to Project Maintainers, Group Owners, and above.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-962h-g945-9r98

An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-95xq-v4m2-fq3r

GitLab Grit Gem for Ruby contains a flaw allowing arbitrary commands to be executed

0%
Низкий
почти 4 года назад
github логотип
GHSA-95p8-ccjw-3g7f

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an authenticated developer to hide specially crafted file changes from the WebUI.

CVSS3: 4.6
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-95hp-m576-m42x

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control.

0%
Низкий
почти 4 года назад
github логотип
GHSA-94xw-8rg2-4fmc

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-94fv-wxc5-f8vm

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 3 of 3). When a project with visibility more permissive than the target group is imported, it will retain its prior visibility.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-947f-qh3g-pcj5

An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-9423-j6rv-rhp5

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

0%
Низкий
почти 4 года назад
github логотип
GHSA-93f4-345x-96mm

An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.

CVSS3: 7.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-93c3-fhhf-8qpv

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository in "raw" mode, it can be made to render as HTML if viewed under specific circumstances

CVSS3: 4.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-9396-6m54-w269

An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintainers can exploit a vulnerability where they can assign custom roles to users with permissions exceeding their own, effectively granting themselves elevated privileges.

CVSS3: 3.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-9388-pxcv-qr7p

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-9338-7cq4-hm8v

In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.

0%
Низкий
почти 4 года назад
github логотип
GHSA-92c9-mr48-m5pg

An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes

0%
Низкий
почти 4 года назад
github логотип
GHSA-923w-9p3x-hmgw

Jenkins GitLab Plugin missing permission checks

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-9238-gwm5-6mm9

An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.

CVSS3: 6.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-8xwc-6h6p-hh69

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.

CVSS3: 9.8
0%
Низкий
почти 3 года назад

Уязвимостей на страницу