Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-8c6r-xvww-2p23

почти 4 года назад

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-89x8-fvq4-x5w3

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows an attacker to do a resource exhaustion using GraphQL `vulnerabilitiesCountByDay`

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-89gh-7gfw-7rqp

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1. Insufficient permission checks were being applied when displaying CI results, potentially exposing some CI metrics data to unauthorized users.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-89fg-r5w5-hh2w

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-892p-f7qf-cw7v

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-87x4-89mh-jmjg

почти 4 года назад

A stored Cross-Site Scripting vulnerability in the DataDog integration in GitLab CE/EE version 13.7 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-87v5-hm46-mgp6

около 3 лет назад

An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes user email id through webhook payload.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-87qr-9vj6-hjc5

почти 4 года назад

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-86mr-824x-hfxf

почти 4 года назад

A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-86j2-r9c9-2h84

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression related to quick actions features was susceptible to catastrophic backtracking that could cause a DOS attack.

EPSS: Низкий
github логотип

GHSA-86fp-jr93-hvv2

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-864q-6x2v-wvg4

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control, a different vulnerability than CVE-2019-9732.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-85vj-ffxc-x8w8

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira prefix

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-85ch-gvj9-wmwc

почти 4 года назад

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

EPSS: Низкий
github логотип

GHSA-859x-xr5x-c9x2

больше 1 года назад

A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-857m-xj2v-vhp3

почти 4 года назад

CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners. Affected versions are >=13.5.0, <13.5.2,>=13.4.0, <13.4.5,<13.3.9.

EPSS: Низкий
github логотип

GHSA-8572-xjmw-7fq3

около 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-84m5-rqxq-483p

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-84hw-r4c9-fp45

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 3 of 5).

EPSS: Низкий
github логотип

GHSA-845x-h4jv-2v89

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause Denial of Service by sending specially crafted requests to the Jira events endpoint.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-8c6r-xvww-2p23

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-89x8-fvq4-x5w3

An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows an attacker to do a resource exhaustion using GraphQL `vulnerabilitiesCountByDay`

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-89gh-7gfw-7rqp

An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1. Insufficient permission checks were being applied when displaying CI results, potentially exposing some CI metrics data to unauthorized users.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-89fg-r5w5-hh2w

An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.

CVSS3: 3.5
0%
Низкий
около 1 года назад
github логотип
GHSA-892p-f7qf-cw7v

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook.

CVSS3: 3.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-87x4-89mh-jmjg

A stored Cross-Site Scripting vulnerability in the DataDog integration in GitLab CE/EE version 13.7 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-87v5-hm46-mgp6

An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes user email id through webhook payload.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-87qr-9vj6-hjc5

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-86mr-824x-hfxf

A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-86j2-r9c9-2h84

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression related to quick actions features was susceptible to catastrophic backtracking that could cause a DOS attack.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-86fp-jr93-hvv2

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.

CVSS3: 4
0%
Низкий
больше 1 года назад
github логотип
GHSA-864q-6x2v-wvg4

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control, a different vulnerability than CVE-2019-9732.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-85vj-ffxc-x8w8

An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira prefix

CVSS3: 6.5
2%
Низкий
почти 3 года назад
github логотип
GHSA-85ch-gvj9-wmwc

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

0%
Низкий
почти 4 года назад
github логотип
GHSA-859x-xr5x-c9x2

A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL

CVSS3: 7.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-857m-xj2v-vhp3

CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners. Affected versions are >=13.5.0, <13.5.2,>=13.4.0, <13.4.5,<13.3.9.

0%
Низкий
почти 4 года назад
github логотип
GHSA-8572-xjmw-7fq3

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection.

CVSS3: 6.4
0%
Низкий
около 1 года назад
github логотип
GHSA-84m5-rqxq-483p

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

CVSS3: 6.4
4%
Низкий
около 2 лет назад
github логотип
GHSA-84hw-r4c9-fp45

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 3 of 5).

0%
Низкий
почти 4 года назад
github логотип
GHSA-845x-h4jv-2v89

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause Denial of Service by sending specially crafted requests to the Jira events endpoint.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу