Gitlab

GitLab

1368 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 06.07.2021 21:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:45

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member.

  • EPSS 0.13%
  • Veröffentlicht 06.07.2021 21:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:45

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

  • EPSS 0.19%
  • Veröffentlicht 06.07.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 05:49:44

Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9

Exploit
  • EPSS 0.44%
  • Veröffentlicht 24.06.2021 00:15:08
  • Zuletzt bearbeitet 21.11.2024 06:07:49

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit1000...

Warnung Exploit
  • EPSS 69.74%
  • Veröffentlicht 11.06.2021 16:15:09
  • Zuletzt bearbeitet 18.02.2026 20:07:28

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where re...

  • EPSS 0.17%
  • Veröffentlicht 11.06.2021 16:15:09
  • Zuletzt bearbeitet 21.11.2024 05:49:39

A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources.

  • EPSS 0.17%
  • Veröffentlicht 08.06.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:43

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

  • EPSS 0.15%
  • Veröffentlicht 08.06.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:44

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

  • EPSS 0.68%
  • Veröffentlicht 08.06.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:43

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request

  • EPSS 0.21%
  • Veröffentlicht 08.06.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:44

All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the...