Количество 5 336
Количество 5 336
GHSA-6w8j-8369-mmxr
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
GHSA-6w53-65xx-mgj9
A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.
GHSA-6w2q-694x-ccv5
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for Information Exposure via unsubscribe links in email replies.
GHSA-6vv9-3qmw-8f45
GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue.
GHSA-6vqj-g5rm-3gp4
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables.
GHSA-6v4w-cqrg-xv3g
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 2 of 5).
GHSA-6v2x-53rq-w964
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by creating wiki pages with malicious content.
GHSA-6qcx-wmcg-gqpq
All versions of GitLab CE/EE starting with 12.8 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.
GHSA-6q9r-jfhj-643w
An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance.
GHSA-6q57-rfmx-mxr3
GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,
GHSA-6p8w-9h2c-mmf6
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure.
GHSA-6mwv-mqqw-2j35
An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2).
GHSA-6mpj-fw9g-9wqm
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.
GHSA-6mjw-gpqr-2788
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. The pins endpoint is susceptible to DoS through a crafted request.
GHSA-6jwf-9gvr-hw8m
An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.
GHSA-6jr9-m575-w4wm
An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.
GHSA-6jpw-pq5v-3x7w
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited
GHSA-6j9g-hv65-w2mh
An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Making concurrent GET /api/v4/projects/<id>/languages requests may allow Uncontrolled Resource Consumption.
GHSA-6j5x-6p93-f5m6
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users.
GHSA-6hf8-hv66-q62p
For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-6w8j-8369-mmxr An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control. | 0% Низкий | больше 3 лет назад | ||
GHSA-6w53-65xx-mgj9 A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page. | CVSS3: 6.5 | 0% Низкий | 8 месяцев назад | |
GHSA-6w2q-694x-ccv5 An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for Information Exposure via unsubscribe links in email replies. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-6vv9-3qmw-8f45 GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue. | 0% Низкий | больше 3 лет назад | ||
GHSA-6vqj-g5rm-3gp4 An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables. | CVSS3: 6.4 | 0% Низкий | почти 3 года назад | |
GHSA-6v4w-cqrg-xv3g An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 2 of 5). | CVSS3: 3.7 | 0% Низкий | больше 3 лет назад | |
GHSA-6v2x-53rq-w964 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by creating wiki pages with malicious content. | CVSS3: 8.7 | 0% Низкий | 2 месяца назад | |
GHSA-6qcx-wmcg-gqpq All versions of GitLab CE/EE starting with 12.8 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits. | CVSS3: 2.6 | 0% Низкий | больше 3 лет назад | |
GHSA-6q9r-jfhj-643w An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад | |
GHSA-6q57-rfmx-mxr3 GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother, | 0% Низкий | больше 3 лет назад | ||
GHSA-6p8w-9h2c-mmf6 An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-6mwv-mqqw-2j35 An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2). | 0% Низкий | больше 3 лет назад | ||
GHSA-6mpj-fw9g-9wqm GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection. | CVSS3: 3.5 | 0% Низкий | около 1 месяца назад | |
GHSA-6mjw-gpqr-2788 An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. The pins endpoint is susceptible to DoS through a crafted request. | CVSS3: 6.5 | 2% Низкий | больше 1 года назад | |
GHSA-6jwf-9gvr-hw8m An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization. | 0% Низкий | больше 3 лет назад | ||
GHSA-6jr9-m575-w4wm An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect. | 0% Низкий | больше 3 лет назад | ||
GHSA-6jpw-pq5v-3x7w When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited | 94% Критический | больше 3 лет назад | ||
GHSA-6j9g-hv65-w2mh An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Making concurrent GET /api/v4/projects/<id>/languages requests may allow Uncontrolled Resource Consumption. | 0% Низкий | больше 3 лет назад | ||
GHSA-6j5x-6p93-f5m6 An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users. | CVSS3: 3.7 | 0% Низкий | 10 месяцев назад | |
GHSA-6hf8-hv66-q62p For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу