Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-5xvc-mqqw-gm7p

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It allows Uncontrolled Resource Consumption.

EPSS: Низкий
github логотип

GHSA-5xrw-g5h5-j2r6

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 in which cross-site request forgery may have been possible on GitLab instances configured to use JWT as an OmniAuth provider.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-5xhg-wqm3-8ww2

больше 2 лет назад

An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-5x88-x3vg-442p

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-5x78-2px4-46jf

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template

EPSS: Низкий
github логотип

GHSA-5vxp-7m3v-hxrg

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge request titles.

EPSS: Низкий
github логотип

GHSA-5vpg-xw87-4738

3 месяца назад

An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that, under certain circumstances, could have allowed an attacker to remove Duo flows of another user.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-5rfm-2gcw-59ww

больше 2 лет назад

An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-5qxw-jpqh-h83p

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-5qwh-g35c-5mmm

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.

CVSS3: 3
EPSS: Низкий
github логотип

GHSA-5qpg-r237-3pm4

больше 3 лет назад

GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.

EPSS: Низкий
github логотип

GHSA-5qhc-78h9-5m5x

4 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific descriptions.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-5q5j-r39w-wc64

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-5px4-prjg-wgwv

больше 3 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncontrolled Resource Consumption.

EPSS: Низкий
github логотип

GHSA-5pqm-4gpg-63j8

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-5phj-qv74-pv4w

больше 3 лет назад

Missing permission check in Jenkins GitLab Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-5p95-g2w7-2rfh

больше 3 лет назад

Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code

EPSS: Низкий
github логотип

GHSA-5p8h-m559-wpw7

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-5p89-g2g5-4687

больше 3 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-5p65-6rwr-377w

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-5xvc-mqqw-gm7p

An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It allows Uncontrolled Resource Consumption.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5xrw-g5h5-j2r6

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 in which cross-site request forgery may have been possible on GitLab instances configured to use JWT as an OmniAuth provider.

CVSS3: 6.4
0%
Низкий
около 1 года назад
github логотип
GHSA-5xhg-wqm3-8ww2

An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-5x88-x3vg-442p

An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-5x78-2px4-46jf

An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5vxp-7m3v-hxrg

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge request titles.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5vpg-xw87-4738

An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that, under certain circumstances, could have allowed an attacker to remove Duo flows of another user.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-5rfm-2gcw-59ww

An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-5qxw-jpqh-h83p

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-5qwh-g35c-5mmm

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.

CVSS3: 3
0%
Низкий
больше 1 года назад
github логотип
GHSA-5qpg-r237-3pm4

GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5qhc-78h9-5m5x

GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific descriptions.

CVSS3: 3.7
0%
Низкий
4 месяца назад
github логотип
GHSA-5q5j-r39w-wc64

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.

CVSS3: 7.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-5px4-prjg-wgwv

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncontrolled Resource Consumption.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5pqm-4gpg-63j8

An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-5phj-qv74-pv4w

Missing permission check in Jenkins GitLab Plugin

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-5p95-g2w7-2rfh

Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5p8h-m559-wpw7

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

CVSS3: 3.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-5p89-g2g5-4687

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5p65-6rwr-377w

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.

CVSS3: 7.5
0%
Низкий
4 месяца назад

Уязвимостей на страницу