Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 943

Количество 5 943

github логотип

GHSA-86fp-jr93-hvv2

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-864q-6x2v-wvg4

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control, a different vulnerability than CVE-2019-9732.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-85vj-ffxc-x8w8

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira prefix

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-85ch-gvj9-wmwc

около 4 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

EPSS: Низкий
github логотип

GHSA-859x-xr5x-c9x2

почти 2 года назад

A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-857m-xj2v-vhp3

около 4 лет назад

CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners. Affected versions are >=13.5.0, <13.5.2,>=13.4.0, <13.4.5,<13.3.9.

EPSS: Низкий
github логотип

GHSA-8572-xjmw-7fq3

больше 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-84m5-rqxq-483p

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-84hw-r4c9-fp45

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 3 of 5).

EPSS: Низкий
github логотип

GHSA-845x-h4jv-2v89

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause Denial of Service by sending specially crafted requests to the Jira events endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-83w3-58xf-86mr

около 4 лет назад

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration

EPSS: Низкий
github логотип

GHSA-83vq-89q3-896f

около 1 года назад

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated users with invitation privileges to bypass group-level user invitation restrictions by manipulating group invitation functionality.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-8395-cmcp-8vmc

около 4 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead to NuGet package and file disclosure (Exposure of Sensitive Information) via request smuggling.

EPSS: Низкий
github логотип

GHSA-8372-vr6c-f48r

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.1 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. It was possible for an attacker to cause a denial of service using maliciously crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8322-7g6r-mw9p

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that could have allowed an authenticated user to cause denial of service on the CI/CD Catalog page due to improper sanitization.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-82v9-h229-pq5f

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API requests, potentially leading to resource abuse and unauthorized content storage.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-7xp2-7fx4-46xp

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-7x5p-82gv-c93r

6 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to cause Denial of Service by uploading a malicious file and repeatedly querying it through GraphQl.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-7x52-3x7c-gwj6

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-7wc9-4gpr-w6xx

больше 1 года назад

Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions on critical project data.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-86fp-jr93-hvv2

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.

CVSS3: 4
0%
Низкий
больше 1 года назад
github логотип
GHSA-864q-6x2v-wvg4

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control, a different vulnerability than CVE-2019-9732.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-85vj-ffxc-x8w8

An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira prefix

CVSS3: 6.5
2%
Низкий
около 3 лет назад
github логотип
GHSA-85ch-gvj9-wmwc

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

1%
Низкий
около 4 лет назад
github логотип
GHSA-859x-xr5x-c9x2

A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL

CVSS3: 7.7
1%
Низкий
почти 2 года назад
github логотип
GHSA-857m-xj2v-vhp3

CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners. Affected versions are >=13.5.0, <13.5.2,>=13.4.0, <13.4.5,<13.3.9.

1%
Низкий
около 4 лет назад
github логотип
GHSA-8572-xjmw-7fq3

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-84m5-rqxq-483p

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

CVSS3: 6.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-84hw-r4c9-fp45

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 3 of 5).

0%
Низкий
около 4 лет назад
github логотип
GHSA-845x-h4jv-2v89

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause Denial of Service by sending specially crafted requests to the Jira events endpoint.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-83w3-58xf-86mr

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration

1%
Низкий
около 4 лет назад
github логотип
GHSA-83vq-89q3-896f

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated users with invitation privileges to bypass group-level user invitation restrictions by manipulating group invitation functionality.

CVSS3: 2.7
0%
Низкий
около 1 года назад
github логотип
GHSA-8395-cmcp-8vmc

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead to NuGet package and file disclosure (Exposure of Sensitive Information) via request smuggling.

1%
Низкий
около 4 лет назад
github логотип
GHSA-8372-vr6c-f48r

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.1 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. It was possible for an attacker to cause a denial of service using maliciously crafted file.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-8322-7g6r-mw9p

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that could have allowed an authenticated user to cause denial of service on the CI/CD Catalog page due to improper sanitization.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-82v9-h229-pq5f

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API requests, potentially leading to resource abuse and unauthorized content storage.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-7xp2-7fx4-46xp

An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.

CVSS3: 5.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-7x5p-82gv-c93r

GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to cause Denial of Service by uploading a malicious file and repeatedly querying it through GraphQl.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-7x52-3x7c-gwj6

An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-7wc9-4gpr-w6xx

Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions on critical project data.

CVSS3: 4.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу