Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-727w-x522-pvpc

почти 4 года назад

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-722v-49rj-hh57

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. The main branch of a repository with a specially designed name allows an attacker to create repositories with malicious code.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-6xw3-8926-pq6q

почти 4 года назад

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

EPSS: Низкий
github логотип

GHSA-6xr7-mv6q-jx4q

около 1 года назад

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-6xcc-cmr2-r357

почти 4 года назад

GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.

EPSS: Низкий
github логотип

GHSA-6x9x-gp76-v665

почти 4 года назад

A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Windows system with a docker executor, which allows the attacker to run arbitrary commands on Windows host, via DOCKER_AUTH_CONFIG build variable.

EPSS: Низкий
github логотип

GHSA-6x4g-3g6f-c363

почти 4 года назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure.

EPSS: Низкий
github логотип

GHSA-6wrg-vxvm-8pr3

почти 4 года назад

GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users.

EPSS: Низкий
github логотип

GHSA-6wgj-fxqf-wxj2

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-6w8j-8369-mmxr

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-6w53-65xx-mgj9

9 месяцев назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6w2q-694x-ccv5

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for Information Exposure via unsubscribe links in email replies.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-6vv9-3qmw-8f45

почти 4 года назад

GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue.

EPSS: Низкий
github логотип

GHSA-6vqj-g5rm-3gp4

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-6v4w-cqrg-xv3g

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 2 of 5).

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-6v2x-53rq-w964

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by creating wiki pages with malicious content.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-6qcx-wmcg-gqpq

почти 4 года назад

All versions of GitLab CE/EE starting with 12.8 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-6q9r-jfhj-643w

больше 3 лет назад

An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-6q57-rfmx-mxr3

почти 4 года назад

GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,

EPSS: Низкий
github логотип

GHSA-6p8w-9h2c-mmf6

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-727w-x522-pvpc

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-722v-49rj-hh57

An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. The main branch of a repository with a specially designed name allows an attacker to create repositories with malicious code.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-6xw3-8926-pq6q

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

0%
Низкий
почти 4 года назад
github логотип
GHSA-6xr7-mv6q-jx4q

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

CVSS3: 3.1
0%
Низкий
около 1 года назад
github логотип
GHSA-6xcc-cmr2-r357

GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.

0%
Низкий
почти 4 года назад
github логотип
GHSA-6x9x-gp76-v665

A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Windows system with a docker executor, which allows the attacker to run arbitrary commands on Windows host, via DOCKER_AUTH_CONFIG build variable.

1%
Низкий
почти 4 года назад
github логотип
GHSA-6x4g-3g6f-c363

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure.

0%
Низкий
почти 4 года назад
github логотип
GHSA-6wrg-vxvm-8pr3

GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users.

0%
Низкий
почти 4 года назад
github логотип
GHSA-6wgj-fxqf-wxj2

An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-6w8j-8369-mmxr

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

0%
Низкий
почти 4 года назад
github логотип
GHSA-6w53-65xx-mgj9

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-6w2q-694x-ccv5

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for Information Exposure via unsubscribe links in email replies.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-6vv9-3qmw-8f45

GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue.

0%
Низкий
почти 4 года назад
github логотип
GHSA-6vqj-g5rm-3gp4

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables.

CVSS3: 6.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-6v4w-cqrg-xv3g

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 2 of 5).

CVSS3: 3.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-6v2x-53rq-w964

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by creating wiki pages with malicious content.

CVSS3: 8.7
0%
Низкий
4 месяца назад
github логотип
GHSA-6qcx-wmcg-gqpq

All versions of GitLab CE/EE starting with 12.8 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
0%
Низкий
почти 4 года назад
github логотип
GHSA-6q9r-jfhj-643w

An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-6q57-rfmx-mxr3

GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,

0%
Низкий
почти 4 года назад
github логотип
GHSA-6p8w-9h2c-mmf6

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure.

CVSS3: 7.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу