Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-8xr4-8v2f-pqrx

около 1 года назад

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8wmm-qgmm-95gm

почти 4 года назад

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

EPSS: Низкий
github логотип

GHSA-8wjh-279q-q77p

почти 4 года назад

GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.

EPSS: Низкий
github логотип

GHSA-8wjf-7pjq-2695

почти 4 года назад

A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.

EPSS: Низкий
github логотип

GHSA-8wgj-rmmm-5w93

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. A user retains their role within a project in a private group after being removed from the group, if their privileges within the project are different from the group.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8w99-w8qh-2732

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 5 of 5).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-8w2x-795m-pv4v

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A specially crafted payload could lead to a reflected XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims on self-hosted instances running without strict CSP.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-8vgc-gxvf-cqfp

почти 4 года назад

GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in the OAuth authorization page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-8rmw-8cch-2w5c

около 1 года назад

An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions via a change page.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-8r73-cjhp-chc2

почти 4 года назад

GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files (tar). All GitLab versions prior to 8.13.0 restricted this feature to administrators only. Starting with version 8.13.0 this feature was made available to all users. This feature did not properly check for symbolic links in user-provided archives and therefore it was possible for an authenticated user to retrieve the contents of any file accessible to the GitLab service account. This included sensitive files such as those that contain secret tokens used by the GitLab service to authenticate users. GitLab CE and EE versions 8.13.0 through 8.13.2, 8.12.0 through 8.12.7, 8.11.0 through 8.11.10, 8.10.0 through 8.10.12, and 8.9.0 through 8.9.11 are affected.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-8r4j-q2x9-54v8

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-8r38-jrwh-8grw

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-8qwm-jfc5-4g8q

почти 4 года назад

GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via Mermaid.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-8qr9-mc3w-88c6

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. An AI feature was found to read unsanitized content in a way that could have allowed an attacker to hide prompt injection.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-8qm7-f87m-vr5v

почти 4 года назад

GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group to add themselves to any project that is inside a subgroup.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-8qgm-5447-jmq4

9 месяцев назад

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-8q6j-vjqp-vjff

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-8q2m-xg6f-pf6x

почти 4 года назад

A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.

EPSS: Низкий
github логотип

GHSA-8p74-f253-3hw4

почти 4 года назад

An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard.

EPSS: Низкий
github логотип

GHSA-8mrc-cw5j-72jw

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-8xr4-8v2f-pqrx

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-8wmm-qgmm-95gm

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

0%
Низкий
почти 4 года назад
github логотип
GHSA-8wjh-279q-q77p

GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.

0%
Низкий
почти 4 года назад
github логотип
GHSA-8wjf-7pjq-2695

A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.

0%
Низкий
почти 4 года назад
github логотип
GHSA-8wgj-rmmm-5w93

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. A user retains their role within a project in a private group after being removed from the group, if their privileges within the project are different from the group.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-8w99-w8qh-2732

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 5 of 5).

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-8w2x-795m-pv4v

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A specially crafted payload could lead to a reflected XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims on self-hosted instances running without strict CSP.

CVSS3: 6.1
25%
Средний
почти 3 года назад
github логотип
GHSA-8vgc-gxvf-cqfp

GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in the OAuth authorization page.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-8rmw-8cch-2w5c

An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions via a change page.

CVSS3: 8.7
1%
Низкий
около 1 года назад
github логотип
GHSA-8r73-cjhp-chc2

GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files (tar). All GitLab versions prior to 8.13.0 restricted this feature to administrators only. Starting with version 8.13.0 this feature was made available to all users. This feature did not properly check for symbolic links in user-provided archives and therefore it was possible for an authenticated user to retrieve the contents of any file accessible to the GitLab service account. This included sensitive files such as those that contain secret tokens used by the GitLab service to authenticate users. GitLab CE and EE versions 8.13.0 through 8.13.2, 8.12.0 through 8.12.7, 8.11.0 through 8.11.10, 8.10.0 through 8.10.12, and 8.9.0 through 8.9.11 are affected.

CVSS3: 6.5
13%
Средний
почти 4 года назад
github логотип
GHSA-8r4j-q2x9-54v8

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.

CVSS3: 8.7
2%
Низкий
больше 1 года назад
github логотип
GHSA-8r38-jrwh-8grw

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.

CVSS3: 8.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-8qwm-jfc5-4g8q

GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via Mermaid.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-8qr9-mc3w-88c6

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. An AI feature was found to read unsanitized content in a way that could have allowed an attacker to hide prompt injection.

CVSS3: 3.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-8qm7-f87m-vr5v

GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group to add themselves to any project that is inside a subgroup.

CVSS3: 6.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-8qgm-5447-jmq4

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 8.7
0%
Низкий
9 месяцев назад
github логотип
GHSA-8q6j-vjqp-vjff

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-8q2m-xg6f-pf6x

A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.

0%
Низкий
почти 4 года назад
github логотип
GHSA-8p74-f253-3hw4

An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard.

0%
Низкий
почти 4 года назад
github логотип
GHSA-8mrc-cw5j-72jw

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу