Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-6mwv-mqqw-2j35

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2).

EPSS: Низкий
github логотип

GHSA-6mr8-cjxv-868w

19 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by issuing specially crafted requests to repository archive endpoints under certain conditions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6mpj-fw9g-9wqm

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-6mjw-gpqr-2788

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. The pins endpoint is susceptible to DoS through a crafted request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6jwf-9gvr-hw8m

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.

EPSS: Низкий
github логотип

GHSA-6jr9-m575-w4wm

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.

EPSS: Низкий
github логотип

GHSA-6jpw-pq5v-3x7w

почти 4 года назад

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

EPSS: Критический
github логотип

GHSA-6j9g-hv65-w2mh

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Making concurrent GET /api/v4/projects/<id>/languages requests may allow Uncontrolled Resource Consumption.

EPSS: Низкий
github логотип

GHSA-6j5x-6p93-f5m6

12 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-6hv2-5mwg-mjjf

19 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause repository downloads to contain different code than displayed in the web interface due to incorrect validation of branch references under certain circumstances.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-6hf8-hv66-q62p

почти 4 года назад

For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature

EPSS: Низкий
github логотип

GHSA-6hch-mpjp-2743

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to trigger a Regular Expression Denial of Service via a `Cargo.toml` containing maliciously crafted input.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6gm9-64qv-5qwj

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of service vulnerability could allow an attacker to cause a system reboot under certain conditions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6gjc-rr77-h8h6

почти 4 года назад

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-6gf9-9hhg-h494

около 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-6g79-3r2c-5vxg

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,

EPSS: Низкий
github логотип

GHSA-6fvc-pc2f-vcp7

почти 4 года назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance.

EPSS: Низкий
github логотип

GHSA-6f6c-487w-2449

больше 2 лет назад

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-6cxq-rcp9-rqr8

почти 4 года назад

Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.

EPSS: Низкий
github логотип

GHSA-6cqm-3f66-qr6j

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-6mwv-mqqw-2j35

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2).

0%
Низкий
почти 4 года назад
github логотип
GHSA-6mr8-cjxv-868w

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by issuing specially crafted requests to repository archive endpoints under certain conditions.

CVSS3: 7.5
0%
Низкий
19 дней назад
github логотип
GHSA-6mpj-fw9g-9wqm

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

CVSS3: 3.5
0%
Низкий
3 месяца назад
github логотип
GHSA-6mjw-gpqr-2788

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. The pins endpoint is susceptible to DoS through a crafted request.

CVSS3: 6.5
2%
Низкий
почти 2 года назад
github логотип
GHSA-6jwf-9gvr-hw8m

An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.

0%
Низкий
почти 4 года назад
github логотип
GHSA-6jr9-m575-w4wm

An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.

0%
Низкий
почти 4 года назад
github логотип
GHSA-6jpw-pq5v-3x7w

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

94%
Критический
почти 4 года назад
github логотип
GHSA-6j9g-hv65-w2mh

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Making concurrent GET /api/v4/projects/<id>/languages requests may allow Uncontrolled Resource Consumption.

0%
Низкий
почти 4 года назад
github логотип
GHSA-6j5x-6p93-f5m6

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users.

CVSS3: 3.7
0%
Низкий
12 месяцев назад
github логотип
GHSA-6hv2-5mwg-mjjf

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause repository downloads to contain different code than displayed in the web interface due to incorrect validation of branch references under certain circumstances.

CVSS3: 4.1
0%
Низкий
19 дней назад
github логотип
GHSA-6hf8-hv66-q62p

For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature

0%
Низкий
почти 4 года назад
github логотип
GHSA-6hch-mpjp-2743

An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to trigger a Regular Expression Denial of Service via a `Cargo.toml` containing maliciously crafted input.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-6gm9-64qv-5qwj

An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of service vulnerability could allow an attacker to cause a system reboot under certain conditions.

CVSS3: 6.5
2%
Низкий
около 1 года назад
github логотип
GHSA-6gjc-rr77-h8h6

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-6gf9-9hhg-h494

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims.

CVSS3: 6.1
10%
Средний
около 3 лет назад
github логотип
GHSA-6g79-3r2c-5vxg

An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,

0%
Низкий
почти 4 года назад
github логотип
GHSA-6fvc-pc2f-vcp7

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance.

0%
Низкий
почти 4 года назад
github логотип
GHSA-6f6c-487w-2449

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-6cxq-rcp9-rqr8

Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.

1%
Низкий
почти 4 года назад
github логотип
GHSA-6cqm-3f66-qr6j

An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу