Gitlab

Gitlab

1257 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 05.10.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:27

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

  • EPSS 0.27%
  • Veröffentlicht 05.10.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:28

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 05.10.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:28

In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info...

  • EPSS 0.4%
  • Veröffentlicht 05.10.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:29

A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

  • EPSS 0.17%
  • Veröffentlicht 05.10.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:29

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

  • EPSS 0.26%
  • Veröffentlicht 05.10.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:20:25

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

  • EPSS 0.15%
  • Veröffentlicht 05.10.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:20:25

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

  • EPSS 0.2%
  • Veröffentlicht 05.10.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:20:28

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.

  • EPSS 0.25%
  • Veröffentlicht 04.10.2021 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:26

In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands.

  • EPSS 0.18%
  • Veröffentlicht 04.10.2021 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:26

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.