Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-83w3-58xf-86mr

почти 4 года назад

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration

EPSS: Низкий
github логотип

GHSA-83vq-89q3-896f

9 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated users with invitation privileges to bypass group-level user invitation restrictions by manipulating group invitation functionality.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-8395-cmcp-8vmc

почти 4 года назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead to NuGet package and file disclosure (Exposure of Sensitive Information) via request smuggling.

EPSS: Низкий
github логотип

GHSA-8372-vr6c-f48r

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.1 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. It was possible for an attacker to cause a denial of service using maliciously crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-82v9-h229-pq5f

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API requests, potentially leading to resource abuse and unauthorized content storage.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-7xp2-7fx4-46xp

почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-7x5p-82gv-c93r

около 2 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to cause Denial of Service by uploading a malicious file and repeatedly querying it through GraphQl.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-7x52-3x7c-gwj6

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-7wc9-4gpr-w6xx

около 1 года назад

Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions on critical project data.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7w9g-7w46-w7h4

почти 4 года назад

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7w6h-978p-xvrg

почти 4 года назад

A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.

EPSS: Низкий
github логотип

GHSA-7vrg-mmxg-pgfj

почти 4 года назад

GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.

EPSS: Низкий
github логотип

GHSA-7rmh-fw46-g93m

почти 4 года назад

Improper validation of commit author in GitLab CE/EE affecting all versions allowed an attacker to make several pages in a project impossible to view

EPSS: Низкий
github логотип

GHSA-7rfw-87cg-pgwh

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-7rc9-96f5-5rfx

почти 4 года назад

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

EPSS: Низкий
github логотип

GHSA-7q4r-xvh7-hj22

почти 4 года назад

Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7p8p-3gqp-fcqx

почти 4 года назад

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-7p7x-r7pv-gq7p

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to steal tokens and access private repositories by abusing incomplete validation in the Web IDE.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-7p75-9h8v-vxq4

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-7p75-2h87-hjrc

почти 4 года назад

A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-83w3-58xf-86mr

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration

0%
Низкий
почти 4 года назад
github логотип
GHSA-83vq-89q3-896f

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated users with invitation privileges to bypass group-level user invitation restrictions by manipulating group invitation functionality.

CVSS3: 2.7
0%
Низкий
9 месяцев назад
github логотип
GHSA-8395-cmcp-8vmc

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead to NuGet package and file disclosure (Exposure of Sensitive Information) via request smuggling.

0%
Низкий
почти 4 года назад
github логотип
GHSA-8372-vr6c-f48r

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.1 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. It was possible for an attacker to cause a denial of service using maliciously crafted file.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-82v9-h229-pq5f

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API requests, potentially leading to resource abuse and unauthorized content storage.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-7xp2-7fx4-46xp

An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.

CVSS3: 5.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-7x5p-82gv-c93r

GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to cause Denial of Service by uploading a malicious file and repeatedly querying it through GraphQl.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-7x52-3x7c-gwj6

An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-7wc9-4gpr-w6xx

Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions on critical project data.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-7w9g-7w46-w7h4

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-7w6h-978p-xvrg

A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.

0%
Низкий
почти 4 года назад
github логотип
GHSA-7vrg-mmxg-pgfj

GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.

0%
Низкий
почти 4 года назад
github логотип
GHSA-7rmh-fw46-g93m

Improper validation of commit author in GitLab CE/EE affecting all versions allowed an attacker to make several pages in a project impossible to view

0%
Низкий
почти 4 года назад
github логотип
GHSA-7rfw-87cg-pgwh

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

CVSS3: 6.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-7rc9-96f5-5rfx

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

0%
Низкий
почти 4 года назад
github логотип
GHSA-7q4r-xvh7-hj22

Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-7p8p-3gqp-fcqx

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-7p7x-r7pv-gq7p

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to steal tokens and access private repositories by abusing incomplete validation in the Web IDE.

CVSS3: 8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-7p75-9h8v-vxq4

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-7p75-2h87-hjrc

A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.

CVSS3: 7.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу