İçeriğe atla
Noroxi

gitlab kayıtları

gitlab üreticisine ait 1.481 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
5 · %0,3
Silahlaştırılmış
11 · %0,7
Pre-auth RCE
26
Düzeltme kaydı olan
%42
Yayından KEV’e ortanca
194 gün

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

1.481 kayıt
  • An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    gitlab · gitlab23 Nis 2021

  • Weak Password Recovery Mechanism for Forgotten Password in GitLab

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95

    gitlab · gitlab12 Oca 2024

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %91

    gitlab · gitlab11 Eyl 2026

  • When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %53

    gitlab · gitlab11 Haz 2021

  • CVE-2021-39935
    71Bu hafta

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %36

    gitlab · gitlab13 Ara 2021

  • CVE-2022-2992
    65Bu hafta

    A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated us

    KritikCVSS 9,9SilahlaştırılmışEPSS %86

    gitlab · gitlab17 Eki 2022

  • CVE-2022-2884
    62Bu hafta

    A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an auth

    KritikCVSS 9,9Kavram kanıtıEPSS %76

    gitlab · gitlab17 Eki 2022

  • CVE-2022-1162
    62Bu hafta

    A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.

    KritikCVSS 9,8Kavram kanıtıEPSS %76

    gitlab · gitlab4 Nis 2022

  • CVE-2022-2185
    58Planlayın

    A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 pr

    YüksekCVSS 8,8Kavram kanıtıEPSS %77

    gitlab · gitlab1 Tem 2022

  • CVE-2020-13340
    55Planlayın

    An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log

    YüksekCVSS 8,7İstismar yokEPSS %69

    gitlab · gitlab8 Eki 2020

  • CVE-2026-19478
    54Planlayın

    Improper Control of Generation of Code ('Code Injection') in GitLab

    KritikCVSS 9,1Kavram kanıtıEPSS %60

    gitlab · gitlab17 Ağu 2026

  • CVE-2018-14364
    54Planlayın

    GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write ac

    KritikCVSS 9,8İstismar yokEPSS %50

    gitlab · gitlab18 Tem 2018

  • CVE-2023-2825
    51Planlayın

    An issue has been discovered in GitLab CE/EE affecting only version 16.0.0.

    YüksekCVSS 7,5SilahlaştırılmışEPSS %72

    gitlab · gitlab26 May 2023

  • CVE-2023-2442
    50Planlayın

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 befo

    OrtaCVSS 5,4İstismar yokEPSS %96

    gitlab · gitlab7 Haz 2023

  • CVE-2023-0050
    49Planlayın

    An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.

    OrtaCVSS 5,4İstismar yokEPSS %92

    gitlab · gitlab9 Mar 2023

  • CVE-2022-1175
    49Planlayın

    Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versio

    OrtaCVSS 6,1Kavram kanıtıEPSS %82

    gitlab · gitlab4 Nis 2022

  • CVE-2024-1451
    49Planlayın

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

    YüksekCVSS 8,7İstismar yokEPSS %51

    gitlab · gitlab21 Şub 2024

  • CVE-2022-1190
    47Planlayın

    Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an atta

    OrtaCVSS 5,4İstismar yokEPSS %87

    gitlab · gitlab4 Nis 2022

  • CVE-2022-3265
    47Planlayın

    A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prio

    OrtaCVSS 5,4İstismar yokEPSS %86

    gitlab · gitlab9 Kas 2022

  • CVE-2021-4191
    45Planlayın

    An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2.

    OrtaCVSS 5,3SilahlaştırılmışEPSS %80

    gitlab · gitlab28 Mar 2022

  • CVE-2021-22238
    43Planlayın

    An issue has been discovered in GitLab affecting all versions starting with 13.3.

    OrtaCVSS 5,4İstismar yokEPSS %72

    gitlab · gitlab20 Ağu 2021

  • CVE-2023-3364
    43Planlayın

    Inefficient Regular Expression Complexity in GitLab

    YüksekCVSS 7,5İstismar yokEPSS %44

    gitlab · gitlab1 Ağu 2023

  • CVE-2022-0735
    43Planlayın

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 befor

    KritikCVSS 9,8Kavram kanıtıEPSS %13

    gitlab · gitlab28 Mar 2022

  • CVE-2025-5121
    43Planlayın

    Missing Authorization in GitLab

    KritikCVSS 9,9İstismar yokEPSS %12

    gitlab · gitlab20 Haz 2025

  • CVE-2023-0921
    42Planlayın

    Allocation of Resources Without Limits or Throttling in GitLab

    OrtaCVSS 4,3İstismar yokEPSS %84

    gitlab · gitlab6 Haz 2023