Gitlab

GitLab

1474 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.2%
  • Veröffentlicht 20.12.2019 22:15:11
  • Zuletzt bearbeitet 21.11.2024 04:29:04

A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.

Exploit
  • EPSS 0.77%
  • Veröffentlicht 18.12.2019 21:15:14
  • Zuletzt bearbeitet 21.11.2024 04:44:59

An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.

Exploit
  • EPSS 1.51%
  • Veröffentlicht 18.12.2019 21:15:14
  • Zuletzt bearbeitet 21.11.2024 04:45:01

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification require...

Exploit
  • EPSS 1.39%
  • Veröffentlicht 18.12.2019 21:15:14
  • Zuletzt bearbeitet 21.11.2024 04:45:01

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

Exploit
  • EPSS 1.05%
  • Veröffentlicht 18.12.2019 21:15:12
  • Zuletzt bearbeitet 21.11.2024 04:29:04

An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.

Exploit
  • EPSS 1.15%
  • Veröffentlicht 18.12.2019 21:15:12
  • Zuletzt bearbeitet 21.11.2024 04:29:05

An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.

Exploit
  • EPSS 2.41%
  • Veröffentlicht 18.12.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:29:03

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

Exploit
  • EPSS 1.85%
  • Veröffentlicht 18.12.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:29:03

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

Exploit
  • EPSS 0.66%
  • Veröffentlicht 18.12.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:29:03

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.

Exploit
  • EPSS 1.14%
  • Veröffentlicht 18.12.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:29:03

An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipe...