Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-75xv-qqv2-qh22

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4).

EPSS: Низкий
github логотип

GHSA-75xf-j8f2-9vxq

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-75fp-hxc3-f56v

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure.

EPSS: Низкий
github логотип

GHSA-75cm-h3qp-7jq4

около 3 лет назад

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-7579-pf64-fxw7

больше 3 лет назад

A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1

EPSS: Низкий
github логотип

GHSA-74q6-7f58-9g77

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 where an infinite loop exist when an authenticated user with specific rights access a MR having source and target branch pointing to each other

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-74mh-x92q-wp74

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-74cm-4qqj-22p4

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-747q-6mj3-hj66

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. It has Insecure Permissions (issue 3 of 4).

EPSS: Низкий
github логотип

GHSA-73w2-5f6g-jx42

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-73p8-f56m-692w

больше 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-727w-x522-pvpc

больше 3 лет назад

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-722v-49rj-hh57

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. The main branch of a repository with a specially designed name allows an attacker to create repositories with malicious code.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-6xw3-8926-pq6q

больше 3 лет назад

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

EPSS: Низкий
github логотип

GHSA-6xr7-mv6q-jx4q

11 месяцев назад

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-6xcc-cmr2-r357

больше 3 лет назад

GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.

EPSS: Низкий
github логотип

GHSA-6x9x-gp76-v665

больше 3 лет назад

A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Windows system with a docker executor, which allows the attacker to run arbitrary commands on Windows host, via DOCKER_AUTH_CONFIG build variable.

EPSS: Низкий
github логотип

GHSA-6x4g-3g6f-c363

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure.

EPSS: Низкий
github логотип

GHSA-6wrg-vxvm-8pr3

больше 3 лет назад

GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users.

EPSS: Низкий
github логотип

GHSA-6wgj-fxqf-wxj2

около 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-75xv-qqv2-qh22

An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-75xf-j8f2-9vxq

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-75fp-hxc3-f56v

An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-75cm-h3qp-7jq4

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.

CVSS3: 9
0%
Низкий
около 3 лет назад
github логотип
GHSA-7579-pf64-fxw7

A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1

0%
Низкий
больше 3 лет назад
github логотип
GHSA-74q6-7f58-9g77

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 where an infinite loop exist when an authenticated user with specific rights access a MR having source and target branch pointing to each other

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-74mh-x92q-wp74

An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-74cm-4qqj-22p4

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
1%
Низкий
больше 1 года назад
github логотип
GHSA-747q-6mj3-hj66

An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. It has Insecure Permissions (issue 3 of 4).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-73w2-5f6g-jx42

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-73p8-f56m-692w

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-727w-x522-pvpc

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-722v-49rj-hh57

An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. The main branch of a repository with a specially designed name allows an attacker to create repositories with malicious code.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-6xw3-8926-pq6q

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6xr7-mv6q-jx4q

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

CVSS3: 3.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-6xcc-cmr2-r357

GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6x9x-gp76-v665

A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Windows system with a docker executor, which allows the attacker to run arbitrary commands on Windows host, via DOCKER_AUTH_CONFIG build variable.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-6x4g-3g6f-c363

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6wrg-vxvm-8pr3

GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6wgj-fxqf-wxj2

An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.

CVSS3: 4.8
0%
Низкий
около 2 лет назад

Уязвимостей на страницу