Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 943

Количество 5 943

github логотип

GHSA-8qm7-f87m-vr5v

около 4 лет назад

GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group to add themselves to any project that is inside a subgroup.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-8qgm-5447-jmq4

около 1 года назад

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-8q6j-vjqp-vjff

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-8q2m-xg6f-pf6x

около 4 лет назад

A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.

EPSS: Низкий
github логотип

GHSA-8p74-f253-3hw4

около 4 лет назад

An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard.

EPSS: Низкий
github логотип

GHSA-8mrc-cw5j-72jw

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-8m4w-86rm-r3rg

почти 2 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause a denial of service using crafted adoc files.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8m2q-q4c8-7569

около 4 лет назад

Improper authorization checks in GitLab EE > 13.11 allows subgroup members to see epics from all parent subgroups.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-8jx5-64fv-87qh

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause DoS.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8jj8-qh37-33q3

4 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user with Planner role to view security category metadata and attributes in group security configuration due to improper access control

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-8jj6-7vgp-rg47

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-8jc8-cvqj-p926

7 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with guest-role permissions to access test report contents they were not authorized to view due to improper access control enforcement.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-8j2x-wq4x-63v8

около 4 лет назад

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.

EPSS: Низкий
github логотип

GHSA-8hq6-8c4w-ggxc

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request was made in a specific manner.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-8h74-p4xx-m53m

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to delete protected container registry tags due to improper authorization checks.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-8h2p-m6f9-v8r7

около 4 лет назад

A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.

EPSS: Низкий
github логотип

GHSA-8gh5-v944-cphh

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8ggg-8hjr-fmv7

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment on merge requests despite the repository being set to allow only project members to do so.

EPSS: Низкий
github логотип

GHSA-8g4p-8m3f-hfqx

около 4 лет назад

GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read repositories belonging to other users.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8fph-2g4q-jf26

около 4 лет назад

Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any location to access Container Registries even when IP address restrictions were configured.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-8qm7-f87m-vr5v

GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group to add themselves to any project that is inside a subgroup.

CVSS3: 6.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-8qgm-5447-jmq4

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 8.7
0%
Низкий
около 1 года назад
github логотип
GHSA-8q6j-vjqp-vjff

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-8q2m-xg6f-pf6x

A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.

1%
Низкий
около 4 лет назад
github логотип
GHSA-8p74-f253-3hw4

An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard.

1%
Низкий
около 4 лет назад
github логотип
GHSA-8mrc-cw5j-72jw

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-8m4w-86rm-r3rg

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause a denial of service using crafted adoc files.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-8m2q-q4c8-7569

Improper authorization checks in GitLab EE > 13.11 allows subgroup members to see epics from all parent subgroups.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-8jx5-64fv-87qh

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause DoS.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-8jj8-qh37-33q3

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user with Planner role to view security category metadata and attributes in group security configuration due to improper access control

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-8jj6-7vgp-rg47

An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR.

CVSS3: 6.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-8jc8-cvqj-p926

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with guest-role permissions to access test report contents they were not authorized to view due to improper access control enforcement.

CVSS3: 4.3
0%
Низкий
7 дней назад
github логотип
GHSA-8j2x-wq4x-63v8

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.

1%
Низкий
около 4 лет назад
github логотип
GHSA-8hq6-8c4w-ggxc

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request was made in a specific manner.

CVSS3: 4.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-8h74-p4xx-m53m

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to delete protected container registry tags due to improper authorization checks.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-8h2p-m6f9-v8r7

A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.

2%
Низкий
около 4 лет назад
github логотип
GHSA-8gh5-v944-cphh

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-8ggg-8hjr-fmv7

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment on merge requests despite the repository being set to allow only project members to do so.

1%
Низкий
около 4 лет назад
github логотип
GHSA-8g4p-8m3f-hfqx

GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read repositories belonging to other users.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-8fph-2g4q-jf26

Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any location to access Container Registries even when IP address restrictions were configured.

CVSS3: 4.3
1%
Низкий
около 4 лет назад

Уязвимостей на страницу