Gitlab

GitLab

1474 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.58%
  • Veröffentlicht 12.04.2024 01:15:57
  • Zuletzt bearbeitet 11.12.2024 19:29:27

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature a cr...

Exploit
  • EPSS 0.51%
  • Veröffentlicht 12.04.2024 01:15:57
  • Zuletzt bearbeitet 11.12.2024 19:19:05

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbit...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 28.03.2024 08:15:26
  • Zuletzt bearbeitet 11.12.2024 20:26:05

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing a...

  • EPSS 0.95%
  • Veröffentlicht 28.03.2024 08:15:26
  • Zuletzt bearbeitet 11.12.2024 20:25:14

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. It was possible for an attacker to cause a denial of service using mali...

Exploit
  • EPSS 0.71%
  • Veröffentlicht 07.03.2024 01:15:52
  • Zuletzt bearbeitet 11.12.2024 20:12:49

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to...

Exploit
  • EPSS 0.54%
  • Veröffentlicht 07.03.2024 01:15:52
  • Zuletzt bearbeitet 11.12.2024 20:23:27

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privi...

  • EPSS 0.38%
  • Veröffentlicht 22.02.2024 01:15:07
  • Zuletzt bearbeitet 21.11.2024 08:36:12

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. This vulnerability allows for bypassing the 'group ip restric...

  • EPSS 51.47%
  • Veröffentlicht 22.02.2024 00:15:52
  • Zuletzt bearbeitet 21.11.2024 08:50:36

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on ...

  • EPSS 0.45%
  • Veröffentlicht 22.02.2024 00:15:52
  • Zuletzt bearbeitet 21.11.2024 08:50:45

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be...

  • EPSS 0.53%
  • Veröffentlicht 22.02.2024 00:15:51
  • Zuletzt bearbeitet 21.11.2024 08:43:55

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_me...