CVE-2023-3500
- EPSS 0.5%
- Veröffentlicht 02.08.2023 01:15:09
- Zuletzt bearbeitet 21.11.2024 08:17:24
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific Pl...
CVE-2023-3900
- EPSS 0.22%
- Veröffentlicht 02.08.2023 01:15:09
- Zuletzt bearbeitet 21.11.2024 08:18:19
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab woul...
CVE-2023-3993
- EPSS 0.08%
- Veröffentlicht 02.08.2023 01:15:09
- Zuletzt bearbeitet 21.11.2024 08:18:29
An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Access tokens may have been logged when a query was made ...
CVE-2023-3994
- EPSS 0.22%
- Veröffentlicht 02.08.2023 01:15:09
- Zuletzt bearbeitet 21.11.2024 08:18:29
An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via...
CVE-2023-3364
- EPSS 4.71%
- Veröffentlicht 02.08.2023 00:15:18
- Zuletzt bearbeitet 21.11.2024 08:17:06
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible vi...
CVE-2023-3385
- EPSS 0.11%
- Veröffentlicht 02.08.2023 00:15:18
- Zuletzt bearbeitet 21.11.2024 08:17:09
An issue has been discovered in GitLab affecting all versions starting from 8.10 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Under specific circumstances, a user importing a project 'fr...
CVE-2023-0632
- EPSS 0.27%
- Veröffentlicht 02.08.2023 00:15:16
- Zuletzt bearbeitet 21.11.2024 07:37:31
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using...
CVE-2023-1210
- EPSS 0.07%
- Veröffentlicht 02.08.2023 00:15:16
- Zuletzt bearbeitet 21.11.2024 07:38:40
An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message ...
CVE-2023-2164
- EPSS 46.49%
- Veröffentlicht 02.08.2023 00:15:16
- Zuletzt bearbeitet 21.11.2024 07:58:03
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vuln...
CVE-2023-1401
- EPSS 0.1%
- Veröffentlicht 26.07.2023 07:15:09
- Zuletzt bearbeitet 05.05.2025 14:14:52
An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.