Gitlab

Gitlab

1222 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Published 12.09.2024 19:15:04
  • Last modified 21.11.2024 09:50:07

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under c...

  • EPSS 0.13%
  • Published 12.09.2024 19:15:04
  • Last modified 21.11.2024 09:53:01

An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.

  • EPSS 0.06%
  • Published 12.09.2024 19:15:04
  • Last modified 21.11.2024 09:53:29

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLa...

  • EPSS 0.93%
  • Published 12.09.2024 17:15:06
  • Last modified 21.11.2024 09:52:42

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a specific POST request.

  • EPSS 0.02%
  • Published 12.09.2024 17:15:06
  • Last modified 21.11.2024 09:53:28

A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated...

  • EPSS 0.04%
  • Published 12.09.2024 17:15:06
  • Last modified 21.11.2024 09:53:28

A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal res...

  • EPSS 0.16%
  • Published 12.09.2024 17:15:06
  • Last modified 21.11.2024 09:53:29

An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject commands into a connected Cub...

  • EPSS 0.01%
  • Published 12.09.2024 17:15:06
  • Last modified 14.09.2024 15:40:20

An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. An improper input validation error allows attacker to squat on accounts via linking arbitrary unclaimed p...

  • EPSS 0.07%
  • Published 12.09.2024 17:15:05
  • Last modified 21.11.2024 09:47:40

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository...

  • EPSS 0.08%
  • Published 12.09.2024 17:15:05
  • Last modified 21.11.2024 09:49:33

An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a guest user was able to access commit information via the release Atom endpoint, contrary to ...