CVE-2024-7060
- EPSS 0.05%
- Veröffentlicht 24.07.2024 23:15:09
- Zuletzt bearbeitet 21.11.2024 09:50:48
An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.
CVE-2024-6595
- EPSS 0.09%
- Veröffentlicht 17.07.2024 02:15:10
- Zuletzt bearbeitet 21.11.2024 09:49:57
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package dat...
CVE-2024-6385
- EPSS 0.7%
- Veröffentlicht 11.07.2024 07:15:06
- Zuletzt bearbeitet 21.11.2024 09:49:32
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certa...
CVE-2024-5257
- EPSS 0.03%
- Veröffentlicht 11.07.2024 07:15:04
- Zuletzt bearbeitet 21.11.2024 09:47:17
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group name...
CVE-2024-5470
- EPSS 0.05%
- Veröffentlicht 11.07.2024 07:15:04
- Zuletzt bearbeitet 21.11.2024 09:47:44
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.
CVE-2024-2880
- EPSS 0.05%
- Veröffentlicht 11.07.2024 07:15:02
- Zuletzt bearbeitet 21.11.2024 09:10:44
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban ...
CVE-2024-2177
- EPSS 0.14%
- Veröffentlicht 09.07.2024 14:15:03
- Zuletzt bearbeitet 12.12.2024 20:17:46
A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a craf...
CVE-2024-6323
- EPSS 0.07%
- Veröffentlicht 27.06.2024 00:15:13
- Zuletzt bearbeitet 21.11.2024 09:49:25
Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.
CVE-2024-4901
- EPSS 4.79%
- Veröffentlicht 27.06.2024 00:15:12
- Zuletzt bearbeitet 21.11.2024 09:43:49
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with mal...
CVE-2024-5430
- EPSS 0.02%
- Veröffentlicht 27.06.2024 00:15:12
- Zuletzt bearbeitet 21.11.2024 09:47:40
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval p...