Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-6w8j-8369-mmxr

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-6w53-65xx-mgj9

8 месяцев назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6w2q-694x-ccv5

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for Information Exposure via unsubscribe links in email replies.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-6vv9-3qmw-8f45

больше 3 лет назад

GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue.

EPSS: Низкий
github логотип

GHSA-6vqj-g5rm-3gp4

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-6v4w-cqrg-xv3g

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 2 of 5).

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-6v2x-53rq-w964

2 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by creating wiki pages with malicious content.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-6qcx-wmcg-gqpq

больше 3 лет назад

All versions of GitLab CE/EE starting with 12.8 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-6q9r-jfhj-643w

около 3 лет назад

An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-6q57-rfmx-mxr3

больше 3 лет назад

GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,

EPSS: Низкий
github логотип

GHSA-6p8w-9h2c-mmf6

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6mwv-mqqw-2j35

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2).

EPSS: Низкий
github логотип

GHSA-6mpj-fw9g-9wqm

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-6mjw-gpqr-2788

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. The pins endpoint is susceptible to DoS through a crafted request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6jwf-9gvr-hw8m

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.

EPSS: Низкий
github логотип

GHSA-6jr9-m575-w4wm

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.

EPSS: Низкий
github логотип

GHSA-6jpw-pq5v-3x7w

больше 3 лет назад

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

EPSS: Критический
github логотип

GHSA-6j9g-hv65-w2mh

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Making concurrent GET /api/v4/projects/<id>/languages requests may allow Uncontrolled Resource Consumption.

EPSS: Низкий
github логотип

GHSA-6j5x-6p93-f5m6

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-6hf8-hv66-q62p

больше 3 лет назад

For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-6w8j-8369-mmxr

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6w53-65xx-mgj9

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-6w2q-694x-ccv5

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for Information Exposure via unsubscribe links in email replies.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-6vv9-3qmw-8f45

GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6vqj-g5rm-3gp4

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables.

CVSS3: 6.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-6v4w-cqrg-xv3g

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 2 of 5).

CVSS3: 3.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-6v2x-53rq-w964

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by creating wiki pages with malicious content.

CVSS3: 8.7
0%
Низкий
2 месяца назад
github логотип
GHSA-6qcx-wmcg-gqpq

All versions of GitLab CE/EE starting with 12.8 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-6q9r-jfhj-643w

An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-6q57-rfmx-mxr3

GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6p8w-9h2c-mmf6

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-6mwv-mqqw-2j35

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6mpj-fw9g-9wqm

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

CVSS3: 3.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-6mjw-gpqr-2788

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. The pins endpoint is susceptible to DoS through a crafted request.

CVSS3: 6.5
2%
Низкий
больше 1 года назад
github логотип
GHSA-6jwf-9gvr-hw8m

An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6jr9-m575-w4wm

An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6jpw-pq5v-3x7w

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

94%
Критический
больше 3 лет назад
github логотип
GHSA-6j9g-hv65-w2mh

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Making concurrent GET /api/v4/projects/<id>/languages requests may allow Uncontrolled Resource Consumption.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6j5x-6p93-f5m6

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users.

CVSS3: 3.7
0%
Низкий
10 месяцев назад
github логотип
GHSA-6hf8-hv66-q62p

For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу