Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 943

Количество 5 943

github логотип

GHSA-8fgm-gj9v-6jr5

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a Guest user to add an emoji on confidential work items.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-8f9p-2286-5jc9

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-8f66-6ff4-3fj6

около 4 лет назад

Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident.

EPSS: Низкий
github логотип

GHSA-8f5w-v7hr-cxv5

почти 3 года назад

An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-8f3h-5jcr-r8cm

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Критический
github логотип

GHSA-8f2f-6w9m-mg42

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to inject malicious content into project labels titles.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-8cg9-5v35-372m

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-8c9p-4w69-6q42

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that under certain circumstances, could have allowed an unauthenticated user to inject arbitrary scripts into the Mermaid sandbox UI.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-8c93-42cq-rfjj

около 4 лет назад

An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-8c6r-xvww-2p23

около 4 лет назад

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-89x8-fvq4-x5w3

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows an attacker to do a resource exhaustion using GraphQL `vulnerabilitiesCountByDay`

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-89gh-7gfw-7rqp

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1. Insufficient permission checks were being applied when displaying CI results, potentially exposing some CI metrics data to unauthorized users.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-89fg-r5w5-hh2w

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-892p-f7qf-cw7v

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-87x4-89mh-jmjg

около 4 лет назад

A stored Cross-Site Scripting vulnerability in the DataDog integration in GitLab CE/EE version 13.7 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-87v5-hm46-mgp6

больше 3 лет назад

An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes user email id through webhook payload.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-87qr-9vj6-hjc5

около 4 лет назад

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-86r3-q889-hvg2

8 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to view the title of a confidential issue through a publicly accessible merge request due to improper authorization checks.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-86mr-824x-hfxf

около 4 лет назад

A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-86j2-r9c9-2h84

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression related to quick actions features was susceptible to catastrophic backtracking that could cause a DOS attack.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-8fgm-gj9v-6jr5

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a Guest user to add an emoji on confidential work items.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-8f9p-2286-5jc9

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

1%
Низкий
около 4 лет назад
github логотип
GHSA-8f66-6ff4-3fj6

Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident.

1%
Низкий
около 4 лет назад
github логотип
GHSA-8f5w-v7hr-cxv5

An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-8f3h-5jcr-r8cm

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
96%
Критический
около 3 лет назад
github логотип
GHSA-8f2f-6w9m-mg42

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to inject malicious content into project labels titles.

CVSS3: 3.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-8cg9-5v35-372m

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-8c9p-4w69-6q42

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that under certain circumstances, could have allowed an unauthenticated user to inject arbitrary scripts into the Mermaid sandbox UI.

CVSS3: 8
0%
Низкий
5 месяцев назад
github логотип
GHSA-8c93-42cq-rfjj

An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-8c6r-xvww-2p23

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-89x8-fvq4-x5w3

An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows an attacker to do a resource exhaustion using GraphQL `vulnerabilitiesCountByDay`

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-89gh-7gfw-7rqp

An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1. Insufficient permission checks were being applied when displaying CI results, potentially exposing some CI metrics data to unauthorized users.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-89fg-r5w5-hh2w

An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-892p-f7qf-cw7v

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook.

CVSS3: 3.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-87x4-89mh-jmjg

A stored Cross-Site Scripting vulnerability in the DataDog integration in GitLab CE/EE version 13.7 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-87v5-hm46-mgp6

An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes user email id through webhook payload.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-87qr-9vj6-hjc5

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-86r3-q889-hvg2

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to view the title of a confidential issue through a publicly accessible merge request due to improper authorization checks.

CVSS3: 4.3
0%
Низкий
8 дней назад
github логотип
GHSA-86mr-824x-hfxf

A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues

CVSS3: 5.4
6%
Низкий
около 4 лет назад
github логотип
GHSA-86j2-r9c9-2h84

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression related to quick actions features was susceptible to catastrophic backtracking that could cause a DOS attack.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу