Количество 5 336
Количество 5 336
GHSA-6hch-mpjp-2743
An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to trigger a Regular Expression Denial of Service via a `Cargo.toml` containing maliciously crafted input.
GHSA-6gm9-64qv-5qwj
An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of service vulnerability could allow an attacker to cause a system reboot under certain conditions.
GHSA-6gjc-rr77-h8h6
GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.
GHSA-6gf9-9hhg-h494
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims.
GHSA-6g79-3r2c-5vxg
An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,
GHSA-6fvc-pc2f-vcp7
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance.
GHSA-6f6c-487w-2449
A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.
GHSA-6cxq-rcp9-rqr8
Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.
GHSA-6cqm-3f66-qr6j
An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.
GHSA-6cfx-8gfv-h75g
An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrative operations by creating tokens with excessively large names.
GHSA-6cc7-2783-374p
GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.
GHSA-6c6c-hp4f-xg67
In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.
GHSA-6c5h-gg2j-qp46
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.
GHSA-69vx-f9hq-xc87
GitLab before version 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.
GHSA-69v3-jqvw-jq3g
An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was returning contributor emails due to improper data handling in the Datadog integration.
GHSA-6955-m4p2-35rh
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.
GHSA-68v6-4gjc-qv2v
An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details
GHSA-68hg-5q58-g3cv
An information disclosure vulnerability in GitLab CE/EE affecting all versions from 8.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send a crafted request to a backend server to reveal sensitive information.
GHSA-688v-85ch-v3v6
Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.
GHSA-686p-7q3m-4r7x
GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-6hch-mpjp-2743 An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to trigger a Regular Expression Denial of Service via a `Cargo.toml` containing maliciously crafted input. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
GHSA-6gm9-64qv-5qwj An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of service vulnerability could allow an attacker to cause a system reboot under certain conditions. | CVSS3: 6.5 | 2% Низкий | 11 месяцев назад | |
GHSA-6gjc-rr77-h8h6 GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-6gf9-9hhg-h494 A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims. | CVSS3: 6.1 | 11% Средний | около 3 лет назад | |
GHSA-6g79-3r2c-5vxg An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text, | 0% Низкий | больше 3 лет назад | ||
GHSA-6fvc-pc2f-vcp7 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance. | 0% Низкий | больше 3 лет назад | ||
GHSA-6f6c-487w-2449 A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects. | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
GHSA-6cxq-rcp9-rqr8 Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf. | 1% Низкий | больше 3 лет назад | ||
GHSA-6cqm-3f66-qr6j An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details. | CVSS3: 5.4 | 20% Средний | больше 3 лет назад | |
GHSA-6cfx-8gfv-h75g An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrative operations by creating tokens with excessively large names. | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
GHSA-6cc7-2783-374p GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control. | 0% Низкий | больше 3 лет назад | ||
GHSA-6c6c-hp4f-xg67 In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash. | 0% Низкий | больше 3 лет назад | ||
GHSA-6c5h-gg2j-qp46 A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature. | CVSS3: 8.1 | 0% Низкий | почти 4 года назад | |
GHSA-69vx-f9hq-xc87 GitLab before version 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow. | CVSS3: 10 | 0% Низкий | больше 3 лет назад | |
GHSA-69v3-jqvw-jq3g An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was returning contributor emails due to improper data handling in the Datadog integration. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-6955-m4p2-35rh GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API. | 0% Низкий | больше 3 лет назад | ||
GHSA-68v6-4gjc-qv2v An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-68hg-5q58-g3cv An information disclosure vulnerability in GitLab CE/EE affecting all versions from 8.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send a crafted request to a backend server to reveal sensitive information. | CVSS3: 4.3 | 0% Низкий | 12 месяцев назад | |
GHSA-688v-85ch-v3v6 Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
GHSA-686p-7q3m-4r7x GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу