Gitlab

GitLab

1271 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 10.11.2022 00:15:22
  • Zuletzt bearbeitet 21.11.2024 07:20:04

Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user retrying a job in a downstream pipeline to take ownership of the retried jobs in the upstream pipeli...

  • EPSS 0.33%
  • Veröffentlicht 10.11.2022 00:15:22
  • Zuletzt bearbeitet 21.11.2024 07:20:06

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP request...

  • EPSS 0.18%
  • Veröffentlicht 10.11.2022 00:15:22
  • Zuletzt bearbeitet 21.11.2024 07:20:14

An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they don't have ac...

  • EPSS 0.19%
  • Veröffentlicht 10.11.2022 00:15:22
  • Zuletzt bearbeitet 01.05.2025 20:15:34

An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on ...

  • EPSS 0.11%
  • Veröffentlicht 10.11.2022 00:15:22
  • Zuletzt bearbeitet 01.05.2025 20:15:34

An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a malicious users to set emojis on internal notes they don't have access to.

  • EPSS 0.18%
  • Veröffentlicht 10.11.2022 00:15:20
  • Zuletzt bearbeitet 01.05.2025 16:15:22

Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allowed Developers to view the project's Audit Events and Developers or Maintainers ...

  • EPSS 0.35%
  • Veröffentlicht 09.11.2022 23:15:14
  • Zuletzt bearbeitet 21.11.2024 07:19:13

Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab

  • EPSS 0.33%
  • Veröffentlicht 09.11.2022 23:15:14
  • Zuletzt bearbeitet 21.11.2024 07:19:37

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could exfiltrate a Datadog inte...

  • EPSS 0.38%
  • Veröffentlicht 09.11.2022 23:15:14
  • Zuletzt bearbeitet 01.05.2025 20:15:33

An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.

  • EPSS 8.22%
  • Veröffentlicht 09.11.2022 23:15:13
  • Zuletzt bearbeitet 01.05.2025 20:15:32

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead ...