Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 920

Количество 5 920

github логотип

GHSA-9xhf-gx34-9q2g

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-9x8h-2288-5g98

почти 2 года назад

ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of service via Regex backtracking.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9x26-6h4w-rqx8

почти 4 года назад

An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for email invited members to join a project even after the Group Owner has enabled the setting to prevent members from being added to projects in a group, if the invite was sent before the setting was enabled.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-9wrx-mw8f-hx7p

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9wg9-668g-hc95

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressions in GitLab Markdown can exhaust client resources.

EPSS: Низкий
github логотип

GHSA-9wfx-xq2g-33pv

около 4 лет назад

An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9w7f-mwxm-3g85

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a large `glm_source` parameter.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-9w35-73xp-56pr

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline details page allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9vrq-hh79-6v9m

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-9vpf-9m6p-h2rr

около 4 лет назад

An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-9vfc-hfq9-h2v4

около 4 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 10.8 through 12.6.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-9v59-ffhf-ccr8

около 4 лет назад

An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with

EPSS: Низкий
github логотип

GHSA-9v48-rxrr-h9qh

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improved authentication and session management.

EPSS: Низкий
github логотип

GHSA-9rx5-594g-qxq8

около 4 лет назад

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

EPSS: Низкий
github логотип

GHSA-9r89-5vm4-vcr8

около 4 лет назад

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-9r4p-g7c7-2c4r

около 2 лет назад

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-9r3x-jfv9-5w6c

около 4 лет назад

GitLab through 12.7.2 allows XSS.

EPSS: Низкий
github логотип

GHSA-9q79-pqhq-v25q

около 4 лет назад

GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.

EPSS: Низкий
github логотип

GHSA-9q2c-4gv2-vv76

около 4 лет назад

An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue.

EPSS: Низкий
github логотип

GHSA-9pqg-5frc-r6c9

больше 1 года назад

An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-9xhf-gx34-9q2g

An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization

CVSS3: 6.4
1%
Низкий
около 3 лет назад
github логотип
GHSA-9x8h-2288-5g98

ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of service via Regex backtracking.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-9x26-6h4w-rqx8

An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for email invited members to join a project even after the Group Owner has enabled the setting to prevent members from being added to projects in a group, if the invite was sent before the setting was enabled.

CVSS3: 2.7
1%
Низкий
почти 4 года назад
github логотип
GHSA-9wrx-mw8f-hx7p

An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-9wg9-668g-hc95

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressions in GitLab Markdown can exhaust client resources.

2%
Низкий
около 4 лет назад
github логотип
GHSA-9wfx-xq2g-33pv

An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-9w7f-mwxm-3g85

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a large `glm_source` parameter.

CVSS3: 7.5
40%
Средний
почти 2 года назад
github логотип
GHSA-9w35-73xp-56pr

An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline details page allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-9vrq-hh79-6v9m

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.

CVSS3: 4.9
0%
Низкий
около 1 года назад
github логотип
GHSA-9vpf-9m6p-h2rr

An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-9vfc-hfq9-h2v4

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 10.8 through 12.6.1. It has Incorrect Access Control.

1%
Низкий
около 4 лет назад
github логотип
GHSA-9v59-ffhf-ccr8

An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with

1%
Низкий
около 4 лет назад
github логотип
GHSA-9v48-rxrr-h9qh

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improved authentication and session management.

1%
Низкий
около 4 лет назад
github логотип
GHSA-9rx5-594g-qxq8

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

1%
Низкий
около 4 лет назад
github логотип
GHSA-9r89-5vm4-vcr8

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-9r4p-g7c7-2c4r

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

CVSS3: 8
1%
Низкий
около 2 лет назад
github логотип
GHSA-9r3x-jfv9-5w6c

GitLab through 12.7.2 allows XSS.

1%
Низкий
около 4 лет назад
github логотип
GHSA-9q79-pqhq-v25q

GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.

1%
Низкий
около 4 лет назад
github логотип
GHSA-9q2c-4gv2-vv76

An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue.

1%
Низкий
около 4 лет назад
github логотип
GHSA-9pqg-5frc-r6c9

An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.

CVSS3: 8.7
0%
Низкий
больше 1 года назад

Уязвимостей на страницу