Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-7gxg-937v-gfc4

больше 3 лет назад

An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.

EPSS: Низкий
github логотип

GHSA-7ghr-75pj-w6vc

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-7gh6-9wwx-gf4f

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7g53-7whp-2hm3

почти 3 года назад

Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-7g4m-989q-fjvm

почти 3 года назад

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories with malicious code, victims who clone or download these repositories will execute arbitrary code on their systems.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-7g3x-cmv9-pp76

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows SSRF.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-79w6-c88v-gfgr

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.

EPSS: Низкий
github логотип

GHSA-79vw-576r-jwjv

больше 3 лет назад

Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled

EPSS: Низкий
github логотип

GHSA-79rf-9vhj-jq9w

больше 3 лет назад

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

EPSS: Низкий
github логотип

GHSA-79q9-8ff3-x4g2

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2).

EPSS: Низкий
github логотип

GHSA-79gc-8hc2-gp5v

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, commit titles and team member comments could become viewable to users who did not have permission to access these.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7992-h6p9-pc8m

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the branch name during a Web IDE file commit.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-797c-p7mm-pf4h

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-793m-qh53-f8pj

больше 3 лет назад

GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.

EPSS: Низкий
github логотип

GHSA-785p-hcfx-v324

больше 3 лет назад

GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.

EPSS: Низкий
github логотип

GHSA-77qj-2xp7-f745

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-76vq-h32w-9w3v

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one. It has Insecure Permissions.

EPSS: Низкий
github логотип

GHSA-76g9-63cr-m776

около 4 лет назад

Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.x, between 14.5.0 and 14.5.x, and between 14.6.0 and 14.6.x would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configured to run on a port other than 80 or 443

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7668-4r26-7chc

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-762x-jmwj-7xmj

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-7gxg-937v-gfc4

An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-7ghr-75pj-w6vc

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.

CVSS3: 8.7
5%
Низкий
больше 1 года назад
github логотип
GHSA-7gh6-9wwx-gf4f

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-7g53-7whp-2hm3

Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-7g4m-989q-fjvm

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories with malicious code, victims who clone or download these repositories will execute arbitrary code on their systems.

CVSS3: 4.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-7g3x-cmv9-pp76

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows SSRF.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-79w6-c88v-gfgr

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-79vw-576r-jwjv

Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled

0%
Низкий
больше 3 лет назад
github логотип
GHSA-79rf-9vhj-jq9w

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

0%
Низкий
больше 3 лет назад
github логотип
GHSA-79q9-8ff3-x4g2

An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-79gc-8hc2-gp5v

An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, commit titles and team member comments could become viewable to users who did not have permission to access these.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-7992-h6p9-pc8m

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the branch name during a Web IDE file commit.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-797c-p7mm-pf4h

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

CVSS3: 3.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-793m-qh53-f8pj

GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-785p-hcfx-v324

GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-77qj-2xp7-f745

An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-76vq-h32w-9w3v

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one. It has Insecure Permissions.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-76g9-63cr-m776

Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.x, between 14.5.0 and 14.5.x, and between 14.6.0 and 14.6.x would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configured to run on a port other than 80 or 443

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-7668-4r26-7chc

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-762x-jmwj-7xmj

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 6.5
0%
Низкий
около 4 лет назад

Уязвимостей на страницу