Gitlab

GitLab

1271 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 05.10.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:25

In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.

  • EPSS 0.22%
  • Veröffentlicht 05.10.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:26

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

  • EPSS 0.3%
  • Veröffentlicht 05.10.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:26

In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.

  • EPSS 0.19%
  • Veröffentlicht 05.10.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:27

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

  • EPSS 0.1%
  • Veröffentlicht 05.10.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:27

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

  • EPSS 0.27%
  • Veröffentlicht 05.10.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:28

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 05.10.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:28

In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info...

  • EPSS 0.4%
  • Veröffentlicht 05.10.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:29

A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

  • EPSS 0.17%
  • Veröffentlicht 05.10.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:29

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

  • EPSS 0.26%
  • Veröffentlicht 05.10.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:20:25

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.