Gitlab

Gitlab

1257 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 30.12.2019 22:15:11
  • Zuletzt bearbeitet 21.11.2024 04:01:36

An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.

Exploit
  • EPSS 0.12%
  • Veröffentlicht 30.12.2019 22:15:11
  • Zuletzt bearbeitet 21.11.2024 04:01:36

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

  • EPSS 0.11%
  • Veröffentlicht 26.12.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:01:35

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control (issue 2 of 6).

Exploit
  • EPSS 0.11%
  • Veröffentlicht 20.12.2019 22:15:11
  • Zuletzt bearbeitet 21.11.2024 04:29:04

A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.

Exploit
  • EPSS 0.1%
  • Veröffentlicht 18.12.2019 21:15:14
  • Zuletzt bearbeitet 21.11.2024 04:44:59

An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 18.12.2019 21:15:14
  • Zuletzt bearbeitet 21.11.2024 04:45:01

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification require...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 18.12.2019 21:15:14
  • Zuletzt bearbeitet 21.11.2024 04:45:01

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 18.12.2019 21:15:12
  • Zuletzt bearbeitet 21.11.2024 04:29:04

An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 18.12.2019 21:15:12
  • Zuletzt bearbeitet 21.11.2024 04:29:05

An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.

Exploit
  • EPSS 2.68%
  • Veröffentlicht 18.12.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:29:03

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.