Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-6hch-mpjp-2743

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to trigger a Regular Expression Denial of Service via a `Cargo.toml` containing maliciously crafted input.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6gm9-64qv-5qwj

11 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of service vulnerability could allow an attacker to cause a system reboot under certain conditions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6gjc-rr77-h8h6

больше 3 лет назад

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-6gf9-9hhg-h494

около 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-6g79-3r2c-5vxg

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,

EPSS: Низкий
github логотип

GHSA-6fvc-pc2f-vcp7

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance.

EPSS: Низкий
github логотип

GHSA-6f6c-487w-2449

больше 2 лет назад

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-6cxq-rcp9-rqr8

больше 3 лет назад

Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.

EPSS: Низкий
github логотип

GHSA-6cqm-3f66-qr6j

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

CVSS3: 5.4
EPSS: Средний
github логотип

GHSA-6cfx-8gfv-h75g

5 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrative operations by creating tokens with excessively large names.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6cc7-2783-374p

больше 3 лет назад

GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-6c6c-hp4f-xg67

больше 3 лет назад

In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.

EPSS: Низкий
github логотип

GHSA-6c5h-gg2j-qp46

почти 4 года назад

A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-69vx-f9hq-xc87

больше 3 лет назад

GitLab before version 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-69v3-jqvw-jq3g

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was returning contributor emails due to improper data handling in the Datadog integration.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-6955-m4p2-35rh

больше 3 лет назад

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

EPSS: Низкий
github логотип

GHSA-68v6-4gjc-qv2v

больше 3 лет назад

An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-68hg-5q58-g3cv

12 месяцев назад

An information disclosure vulnerability in GitLab CE/EE affecting all versions from 8.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send a crafted request to a backend server to reveal sensitive information.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-688v-85ch-v3v6

5 месяцев назад

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-686p-7q3m-4r7x

больше 3 лет назад

GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-6hch-mpjp-2743

An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to trigger a Regular Expression Denial of Service via a `Cargo.toml` containing maliciously crafted input.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-6gm9-64qv-5qwj

An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of service vulnerability could allow an attacker to cause a system reboot under certain conditions.

CVSS3: 6.5
2%
Низкий
11 месяцев назад
github логотип
GHSA-6gjc-rr77-h8h6

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-6gf9-9hhg-h494

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims.

CVSS3: 6.1
11%
Средний
около 3 лет назад
github логотип
GHSA-6g79-3r2c-5vxg

An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6fvc-pc2f-vcp7

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6f6c-487w-2449

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-6cxq-rcp9-rqr8

Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-6cqm-3f66-qr6j

An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

CVSS3: 5.4
20%
Средний
больше 3 лет назад
github логотип
GHSA-6cfx-8gfv-h75g

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrative operations by creating tokens with excessively large names.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-6cc7-2783-374p

GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6c6c-hp4f-xg67

In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6c5h-gg2j-qp46

A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-69vx-f9hq-xc87

GitLab before version 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.

CVSS3: 10
0%
Низкий
больше 3 лет назад
github логотип
GHSA-69v3-jqvw-jq3g

An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was returning contributor emails due to improper data handling in the Datadog integration.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-6955-m4p2-35rh

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-68v6-4gjc-qv2v

An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-68hg-5q58-g3cv

An information disclosure vulnerability in GitLab CE/EE affecting all versions from 8.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send a crafted request to a backend server to reveal sensitive information.

CVSS3: 4.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-688v-85ch-v3v6

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-686p-7q3m-4r7x

GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу