Gitlab

GitLab

1474 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.33%
  • Veröffentlicht 25.04.2018 09:29:00
  • Zuletzt bearbeitet 21.11.2024 04:14:20

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

Exploit
  • EPSS 1%
  • Veröffentlicht 05.04.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:15:11

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is...

Exploit
  • EPSS 0.81%
  • Veröffentlicht 05.04.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:15:12

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). Th...

  • EPSS 1.32%
  • Veröffentlicht 24.03.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:14:42

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

  • EPSS 0.9%
  • Veröffentlicht 22.03.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:03:54

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their resp...

  • EPSS 2.86%
  • Veröffentlicht 21.03.2018 20:29:01
  • Zuletzt bearbeitet 21.11.2024 04:05:55

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

  • EPSS 1.39%
  • Veröffentlicht 21.03.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:03:53

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.

  • EPSS 5.62%
  • Veröffentlicht 21.03.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:03:53

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

  • EPSS 5.62%
  • Veröffentlicht 21.03.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:03:53

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

  • EPSS 1.28%
  • Veröffentlicht 21.03.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:03:53

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.