Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-7992-h6p9-pc8m

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the branch name during a Web IDE file commit.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-797c-p7mm-pf4h

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-793m-qh53-f8pj

почти 4 года назад

GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.

EPSS: Низкий
github логотип

GHSA-785p-hcfx-v324

почти 4 года назад

GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.

EPSS: Низкий
github логотип

GHSA-77qj-2xp7-f745

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-76vq-h32w-9w3v

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one. It has Insecure Permissions.

EPSS: Низкий
github логотип

GHSA-76g9-63cr-m776

около 4 лет назад

Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.x, between 14.5.0 and 14.5.x, and between 14.6.0 and 14.6.x would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configured to run on a port other than 80 or 443

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7668-4r26-7chc

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-762x-jmwj-7xmj

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-75xv-qqv2-qh22

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4).

EPSS: Низкий
github логотип

GHSA-75xf-j8f2-9vxq

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-75fp-hxc3-f56v

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure.

EPSS: Низкий
github логотип

GHSA-75cm-h3qp-7jq4

больше 3 лет назад

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-7579-pf64-fxw7

почти 4 года назад

A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1

EPSS: Низкий
github логотип

GHSA-74q6-7f58-9g77

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 where an infinite loop exist when an authenticated user with specific rights access a MR having source and target branch pointing to each other

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-74mh-x92q-wp74

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-74cm-4qqj-22p4

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-747q-6mj3-hj66

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. It has Insecure Permissions (issue 3 of 4).

EPSS: Низкий
github логотип

GHSA-73w2-5f6g-jx42

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-73p8-f56m-692w

почти 2 года назад

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-7992-h6p9-pc8m

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the branch name during a Web IDE file commit.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-797c-p7mm-pf4h

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

CVSS3: 3.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-793m-qh53-f8pj

GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.

0%
Низкий
почти 4 года назад
github логотип
GHSA-785p-hcfx-v324

GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.

0%
Низкий
почти 4 года назад
github логотип
GHSA-77qj-2xp7-f745

An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-76vq-h32w-9w3v

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one. It has Insecure Permissions.

0%
Низкий
почти 4 года назад
github логотип
GHSA-76g9-63cr-m776

Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.x, between 14.5.0 and 14.5.x, and between 14.6.0 and 14.6.x would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configured to run on a port other than 80 or 443

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-7668-4r26-7chc

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-762x-jmwj-7xmj

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-75xv-qqv2-qh22

An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4).

0%
Низкий
почти 4 года назад
github логотип
GHSA-75xf-j8f2-9vxq

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-75fp-hxc3-f56v

An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure.

0%
Низкий
почти 4 года назад
github логотип
GHSA-75cm-h3qp-7jq4

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.

CVSS3: 9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-7579-pf64-fxw7

A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1

0%
Низкий
почти 4 года назад
github логотип
GHSA-74q6-7f58-9g77

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 where an infinite loop exist when an authenticated user with specific rights access a MR having source and target branch pointing to each other

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-74mh-x92q-wp74

An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-74cm-4qqj-22p4

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
1%
Низкий
больше 1 года назад
github логотип
GHSA-747q-6mj3-hj66

An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. It has Insecure Permissions (issue 3 of 4).

0%
Низкий
почти 4 года назад
github логотип
GHSA-73w2-5f6g-jx42

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-73p8-f56m-692w

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

CVSS3: 4.3
0%
Низкий
почти 2 года назад

Уязвимостей на страницу