[vaib25vicky](https://hackerone.com/vaib25vicky)
12 записей с упоминанием · 0 за 12 месяцев · 0 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
26Наблюдать | CVE-2023-3932Эксплойта нет | Incorrect User Management in GitLabgitlab · gitlab · CWE-286 | Средняя6,5 | — | 0,9 % | 3 авг. 2023 г. |
29Наблюдать | CVE-2022-4331Эксплойта нет | An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15gitlab · gitlab · CWE-284 | Высокая7,3 | — | 0,7 % | 9 мар. 2023 г. |
17Наблюдать | CVE-2022-4462Эксплойта нет | An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.gitlab · gitlab | Средняя4,3 | — | 0,7 % | 9 мар. 2023 г. |
30Наблюдать | CVE-2022-2498Эксплойта нет | An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15gitlab · gitlab · CWE-269 | Высокая7,5 | — | 0,8 % | 5 авг. 2022 г. |
32Наблюдать | CVE-2022-2326Эксплойта нет | An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versiogitlab · gitlab · CWE-863 | Высокая8,1 | — | 0,8 % | 5 авг. 2022 г. |
17Наблюдать | CVE-2022-2227Эксплойта нет | Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 priorgitlab · gitlab · CWE-732 | Средняя4,3 | — | 0,8 % | 1 июл. 2022 г. |
31Наблюдать | CVE-2020-26413Proof of concept | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2.gitlab · gitlab · CWE-200 | Средняя5,3 | — | 34,9 % | 11 дек. 2020 г. |
26Наблюдать | CVE-2020-13351Эксплойта нет | Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for schegitlab · gitlab · CWE-276 | Средняя6,5 | — | 1,4 % | 17 нояб. 2020 г. |
26Наблюдать | CVE-2020-13346Эксплойта нет | Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to agitlab · gitlab · CWE-459 | Средняя6,5 | — | 1,3 % | 7 окт. 2020 г. |
26Наблюдать | CVE-2020-13320Эксплойта нет | An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project segitlab · gitlab | Средняя6,5 | — | 1,0 % | 30 сент. 2020 г. |
17Наблюдать | CVE-2020-13316Эксплойта нет | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.gitlab · gitlab | Средняя4,3 | — | 1,4 % | 14 сент. 2020 г. |
32Наблюдать | CVE-2020-13299Эксплойта нет | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.gitlab · gitlab · CWE-613 | Высокая8,1 | — | 1,2 % | 14 сент. 2020 г. |
- CVE-2023-393226Наблюдать
Incorrect User Management in GitLab
СредняяCVSS 6,5Эксплойта нетEPSS 1 %gitlab · gitlab3 авг. 2023 г.
- CVE-2022-433129Наблюдать
An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15
ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %gitlab · gitlab9 мар. 2023 г.
- CVE-2022-446217Наблюдать
An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.
СредняяCVSS 4,3Эксплойта нетEPSS 1 %gitlab · gitlab9 мар. 2023 г.
- CVE-2022-249830Наблюдать
An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gitlab · gitlab5 авг. 2022 г.
- CVE-2022-232632Наблюдать
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versio
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %gitlab · gitlab5 авг. 2022 г.
- CVE-2022-222717Наблюдать
Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior
СредняяCVSS 4,3Эксплойта нетEPSS 1 %gitlab · gitlab1 июл. 2022 г.
- CVE-2020-2641331Наблюдать
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2.
СредняяCVSS 5,3Proof of conceptEPSS 35 %gitlab · gitlab11 дек. 2020 г.
- CVE-2020-1335126Наблюдать
Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for sche
СредняяCVSS 6,5Эксплойта нетEPSS 1 %gitlab · gitlab17 нояб. 2020 г.
- CVE-2020-1334626Наблюдать
Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to a
СредняяCVSS 6,5Эксплойта нетEPSS 1 %gitlab · gitlab7 окт. 2020 г.
- CVE-2020-1332026Наблюдать
An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project se
СредняяCVSS 6,5Эксплойта нетEPSS 1 %gitlab · gitlab30 сент. 2020 г.
- CVE-2020-1331617Наблюдать
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
СредняяCVSS 4,3Эксплойта нетEPSS 1 %gitlab · gitlab14 сент. 2020 г.
- CVE-2020-1329932Наблюдать
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %gitlab · gitlab14 сент. 2020 г.