Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 943

Количество 5 943

github логотип

GHSA-7w9g-7w46-w7h4

около 4 лет назад

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7w6h-978p-xvrg

около 4 лет назад

A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.

EPSS: Низкий
github логотип

GHSA-7vrg-mmxg-pgfj

около 4 лет назад

GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.

EPSS: Низкий
github логотип

GHSA-7rmh-fw46-g93m

около 4 лет назад

Improper validation of commit author in GitLab CE/EE affecting all versions allowed an attacker to make several pages in a project impossible to view

EPSS: Низкий
github логотип

GHSA-7rfw-87cg-pgwh

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-7rc9-96f5-5rfx

около 4 лет назад

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

EPSS: Низкий
github логотип

GHSA-7q4r-xvh7-hj22

около 4 лет назад

Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7p8p-3gqp-fcqx

около 4 лет назад

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-7p7x-r7pv-gq7p

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to steal tokens and access private repositories by abusing incomplete validation in the Web IDE.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-7p75-9h8v-vxq4

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-7p75-2h87-hjrc

больше 4 лет назад

A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-7mrh-q55x-m4mh

около 4 лет назад

GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge requests.

EPSS: Низкий
github логотип

GHSA-7mq5-3vcf-v96v

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to hide changes from merge request diff views due to improper input handling of file names.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-7m6x-h8vx-f72m

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7jqp-vcg7-7x84

почти 3 года назад

Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7jgw-fhvx-qfxf

около 4 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-7j3x-j5f8-qr4f

29 дней назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with auditor-level access to modify compliance violation records due to improper authorization on certain GraphQL operations.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-7hxr-jf55-63c7

3 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to execute arbitrary JavaScript in other users' browsers due to improper input sanitization.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-7hvx-c862-6p8m

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

EPSS: Низкий
github логотип

GHSA-7hm8-3c6v-r562

около 4 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted in the Advanced Search feature susceptible to catastrophic backtracking. Affected versions are >=8.12, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-7w9g-7w46-w7h4

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-7w6h-978p-xvrg

A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.

1%
Низкий
около 4 лет назад
github логотип
GHSA-7vrg-mmxg-pgfj

GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.

1%
Низкий
около 4 лет назад
github логотип
GHSA-7rmh-fw46-g93m

Improper validation of commit author in GitLab CE/EE affecting all versions allowed an attacker to make several pages in a project impossible to view

1%
Низкий
около 4 лет назад
github логотип
GHSA-7rfw-87cg-pgwh

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

CVSS3: 6.8
0%
Низкий
около 1 года назад
github логотип
GHSA-7rc9-96f5-5rfx

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

1%
Низкий
около 4 лет назад
github логотип
GHSA-7q4r-xvh7-hj22

Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-7p8p-3gqp-fcqx

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-7p7x-r7pv-gq7p

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to steal tokens and access private repositories by abusing incomplete validation in the Web IDE.

CVSS3: 8
0%
Низкий
6 месяцев назад
github логотип
GHSA-7p75-9h8v-vxq4

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-7p75-2h87-hjrc

A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-7mrh-q55x-m4mh

GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge requests.

1%
Низкий
около 4 лет назад
github логотип
GHSA-7mq5-3vcf-v96v

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to hide changes from merge request diff views due to improper input handling of file names.

CVSS3: 3.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-7m6x-h8vx-f72m

An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-7jqp-vcg7-7x84

Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

CVSS3: 4.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-7jgw-fhvx-qfxf

An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue.

CVSS3: 7
4%
Низкий
около 4 лет назад
github логотип
GHSA-7j3x-j5f8-qr4f

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with auditor-level access to modify compliance violation records due to improper authorization on certain GraphQL operations.

CVSS3: 2.7
0%
Низкий
29 дней назад
github логотип
GHSA-7hxr-jf55-63c7

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to execute arbitrary JavaScript in other users' browsers due to improper input sanitization.

CVSS3: 8.7
0%
Низкий
3 месяца назад
github логотип
GHSA-7hvx-c862-6p8m

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

1%
Низкий
около 4 лет назад
github логотип
GHSA-7hm8-3c6v-r562

An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted in the Advanced Search feature susceptible to catastrophic backtracking. Affected versions are >=8.12, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу