Gitlab

Gitlab

1257 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 10.03.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:24:01

An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It allows Uncontrolled Resource Consumption.

  • EPSS 0.07%
  • Veröffentlicht 10.03.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:24:01

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.

  • EPSS 0.07%
  • Veröffentlicht 10.03.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:24:14

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.

  • EPSS 0.07%
  • Veröffentlicht 10.03.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:24:00

An issue was discovered in GitLab Community and Enterprise Edition 9.0 and through 12.0.2. Users with access to issues, but not the repository were able to view the number of related merge requests on an issue. It has Incorrect Access Control.

  • EPSS 0.1%
  • Veröffentlicht 10.03.2020 15:15:15
  • Zuletzt bearbeitet 21.11.2024 04:22:51

An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability.

  • EPSS 0.09%
  • Veröffentlicht 10.03.2020 15:15:15
  • Zuletzt bearbeitet 21.11.2024 04:22:51

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.

  • EPSS 0.08%
  • Veröffentlicht 10.03.2020 15:15:15
  • Zuletzt bearbeitet 21.11.2024 04:22:51

An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.

  • EPSS 0.08%
  • Veröffentlicht 10.03.2020 15:15:15
  • Zuletzt bearbeitet 21.11.2024 04:23:59

An issue was discovered in GitLab Community and Enterprise Edition 11.9 and later through 12.0.2. GitLab Snippets were vulnerable to an authorization issue that allowed unauthorized users to add comments to a private snippet. It allows authentication...

  • EPSS 0.04%
  • Veröffentlicht 10.03.2020 15:15:15
  • Zuletzt bearbeitet 21.11.2024 04:23:59

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. Unauthorized users were able to read pipeline information of the last merge request. It has Incorrect Access Control.

  • EPSS 0.05%
  • Veröffentlicht 10.03.2020 15:15:15
  • Zuletzt bearbeitet 21.11.2024 04:24:00

An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Uncontrolled Resource Consumption.