Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-684f-v2x3-54c8

больше 3 лет назад

GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR).

EPSS: Низкий
github логотип

GHSA-67r7-3vf2-fjcp

больше 3 лет назад

A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it

EPSS: Низкий
github логотип

GHSA-67pm-cqhh-vcqx

больше 3 лет назад

GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.

EPSS: Низкий
github логотип

GHSA-66xf-5qxv-jmgr

почти 4 года назад

Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-66vj-p7rx-6jrr

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.

EPSS: Низкий
github логотип

GHSA-66h6-4ppg-82p8

больше 3 лет назад

Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.

EPSS: Низкий
github логотип

GHSA-66cv-679x-3ffv

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure direct object reference.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-662c-cj8q-qc4g

больше 1 года назад

An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassing the password re-entry requirement to approve a policy.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-65v8-8343-jcqr

около 4 лет назад

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-65jc-pvp3-rxq3

около 4 лет назад

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.

EPSS: Низкий
github логотип

GHSA-64x3-qr9c-w6jw

больше 3 лет назад

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-64vr-2vhr-px3r

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-64p4-8fvv-rw89

больше 2 лет назад

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-6482-jw4x-5vc6

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

EPSS: Низкий
github логотип

GHSA-6463-hw74-9748

больше 3 лет назад

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

EPSS: Низкий
github логотип

GHSA-645m-h3pw-m72w

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-637p-mqw3-h377

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration.

EPSS: Низкий
github логотип

GHSA-62f3-w8qm-86g2

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-625m-28mg-rq98

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-6224-476v-jppq

почти 4 года назад

Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-684f-v2x3-54c8

GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-67r7-3vf2-fjcp

A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it

0%
Низкий
больше 3 лет назад
github логотип
GHSA-67pm-cqhh-vcqx

GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-66xf-5qxv-jmgr

Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-66vj-p7rx-6jrr

An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.

0%
Низкий
около 4 лет назад
github логотип
GHSA-66h6-4ppg-82p8

Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-66cv-679x-3ffv

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure direct object reference.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-662c-cj8q-qc4g

An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassing the password re-entry requirement to approve a policy.

CVSS3: 4.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-65v8-8343-jcqr

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-65jc-pvp3-rxq3

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.

0%
Низкий
около 4 лет назад
github логотип
GHSA-64x3-qr9c-w6jw

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-64vr-2vhr-px3r

An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-64p4-8fvv-rw89

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-6482-jw4x-5vc6

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6463-hw74-9748

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-645m-h3pw-m72w

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-637p-mqw3-h377

An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-62f3-w8qm-86g2

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-625m-28mg-rq98

An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-6224-476v-jppq

Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.

CVSS3: 5.4
2%
Низкий
почти 4 года назад

Уязвимостей на страницу