Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-7mrh-q55x-m4mh

почти 4 года назад

GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge requests.

EPSS: Низкий
github логотип

GHSA-7m6x-h8vx-f72m

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7jqp-vcg7-7x84

больше 2 лет назад

Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7jgw-fhvx-qfxf

почти 4 года назад

An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-7hvx-c862-6p8m

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

EPSS: Низкий
github логотип

GHSA-7hm8-3c6v-r562

почти 4 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted in the Advanced Search feature susceptible to catastrophic backtracking. Affected versions are >=8.12, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-7hhv-h469-wc4q

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for project members by authenticating through OAuth providers.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-7h88-fv63-qm6h

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch name could be exposed to unauthorized users.

EPSS: Низкий
github логотип

GHSA-7h3w-v9hh-hp55

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a GraphQL endpoint to attach a malicious runner to any project.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-7gxg-937v-gfc4

почти 4 года назад

An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.

EPSS: Низкий
github логотип

GHSA-7ghr-75pj-w6vc

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-7gh6-9wwx-gf4f

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7g53-7whp-2hm3

почти 3 года назад

Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-7g4m-989q-fjvm

почти 3 года назад

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories with malicious code, victims who clone or download these repositories will execute arbitrary code on their systems.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-7g3x-cmv9-pp76

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows SSRF.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-79w6-c88v-gfgr

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.

EPSS: Низкий
github логотип

GHSA-79vw-576r-jwjv

почти 4 года назад

Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled

EPSS: Низкий
github логотип

GHSA-79rf-9vhj-jq9w

почти 4 года назад

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

EPSS: Низкий
github логотип

GHSA-79q9-8ff3-x4g2

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2).

EPSS: Низкий
github логотип

GHSA-79gc-8hc2-gp5v

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, commit titles and team member comments could become viewable to users who did not have permission to access these.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-7mrh-q55x-m4mh

GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge requests.

0%
Низкий
почти 4 года назад
github логотип
GHSA-7m6x-h8vx-f72m

An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-7jqp-vcg7-7x84

Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-7jgw-fhvx-qfxf

An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue.

CVSS3: 7
5%
Низкий
почти 4 года назад
github логотип
GHSA-7hvx-c862-6p8m

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

0%
Низкий
почти 4 года назад
github логотип
GHSA-7hm8-3c6v-r562

An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted in the Advanced Search feature susceptible to catastrophic backtracking. Affected versions are >=8.12, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

0%
Низкий
почти 4 года назад
github логотип
GHSA-7hhv-h469-wc4q

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for project members by authenticating through OAuth providers.

CVSS3: 3.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-7h88-fv63-qm6h

An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch name could be exposed to unauthorized users.

0%
Низкий
почти 4 года назад
github логотип
GHSA-7h3w-v9hh-hp55

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a GraphQL endpoint to attach a malicious runner to any project.

CVSS3: 9.6
0%
Низкий
почти 3 года назад
github логотип
GHSA-7gxg-937v-gfc4

An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.

0%
Низкий
почти 4 года назад
github логотип
GHSA-7ghr-75pj-w6vc

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.

CVSS3: 8.7
5%
Низкий
почти 2 года назад
github логотип
GHSA-7gh6-9wwx-gf4f

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-7g53-7whp-2hm3

Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-7g4m-989q-fjvm

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories with malicious code, victims who clone or download these repositories will execute arbitrary code on their systems.

CVSS3: 4.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-7g3x-cmv9-pp76

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows SSRF.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-79w6-c88v-gfgr

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.

0%
Низкий
почти 4 года назад
github логотип
GHSA-79vw-576r-jwjv

Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled

0%
Низкий
почти 4 года назад
github логотип
GHSA-79rf-9vhj-jq9w

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

0%
Низкий
почти 4 года назад
github логотип
GHSA-79q9-8ff3-x4g2

An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2).

0%
Низкий
почти 4 года назад
github логотип
GHSA-79gc-8hc2-gp5v

An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, commit titles and team member comments could become viewable to users who did not have permission to access these.

CVSS3: 4.3
0%
Низкий
почти 4 года назад

Уязвимостей на страницу