This vulnerability has been discovered internally by the GitLab team.
105 kredili kayıt · son 12 ayda 0 · 0 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
26İzleyin | CVE-2022-3767İstismar yok | Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every gitlab · dynamic application security testing analyzer · CWE-20 | Orta6,5 | — | %0,8 | 9 Mar 2023 |
26İzleyin | CVE-2022-4206İstismar yok | A sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102, exposing the Authorgitlab · dast api scanner · CWE-200 | Orta6,5 | — | %0,6 | 31 Oca 2023 |
21İzleyin | CVE-2022-4255İstismar yok | An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 whigitlab · gitlab | Orta5,3 | — | %0,5 | 27 Oca 2023 |
30İzleyin | CVE-2022-4205İstismar yok | In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash.gitlab · gitlab · CWE-843 | Yüksek7,5 | — | %0,6 | 27 Oca 2023 |
21İzleyin | CVE-2022-4201İstismar yok | A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to cgitlab · gitlab · CWE-918 | Orta5,3 | — | %0,5 | 27 Oca 2023 |
26İzleyin | CVE-2022-3820İstismar yok | An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2.gitlab · gitlab · CWE-290 | Orta6,5 | — | %0,7 | 26 Oca 2023 |
17İzleyin | CVE-2022-3819İstismar yok | An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15gitlab · gitlab · CWE-863 | Orta4,3 | — | %0,5 | 9 Kas 2022 |
21İzleyin | CVE-2022-3818İstismar yok | An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, agitlab · gitlab · CWE-400 | Orta5,3 | — | %0,7 | 9 Kas 2022 |
21İzleyin | CVE-2022-3793İstismar yok | An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15gitlab · gitlab | Orta5,3 | — | %0,6 | 9 Kas 2022 |
17İzleyin | CVE-2022-3706İstismar yok | Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allogitlab · gitlab | Orta4,3 | — | %0,5 | 9 Kas 2022 |
17İzleyin | CVE-2022-3413İstismar yok | Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4, gitlab · gitlab · CWE-639 | Orta4,3 | — | %0,5 | 9 Kas 2022 |
30İzleyin | CVE-2022-3285İstismar yok | Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 agitlab · gitlab | Yüksek7,5 | — | %0,8 | 9 Kas 2022 |
19İzleyin | CVE-2022-3018İstismar yok | An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 1gitlab · gitlab · CWE-532 | Orta4,9 | — | %0,7 | 28 Eki 2022 |
17İzleyin | CVE-2022-3330İstismar yok | It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.gitlab · gitlab | Orta4,3 | — | %0,6 | 17 Eki 2022 |
17İzleyin | CVE-2022-3325İstismar yok | Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 befgitlab · gitlab · CWE-284 | Orta4,3 | — | %0,5 | 17 Eki 2022 |
17İzleyin | CVE-2022-3293İstismar yok | Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prigitlab · gitlab · CWE-532 | Orta4,3 | — | %0,6 | 17 Eki 2022 |
26İzleyin | CVE-2022-3291İstismar yok | Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.gitlab · gitlab · CWE-502 | Orta6,5 | — | %0,8 | 17 Eki 2022 |
21İzleyin | CVE-2022-3286İstismar yok | Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 algitlab · gitlab · CWE-284 | Orta5,3 | — | %0,5 | 17 Eki 2022 |
29İzleyin | CVE-2022-2533İstismar yok | An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2gitlab · gitlab · CWE-287 | Yüksek7,4 | — | %0,7 | 17 Eki 2022 |
21İzleyin | CVE-2022-2539İstismar yok | An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.6 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 priorgitlab · gitlab | Orta5,3 | — | %0,8 | 5 Ağu 2022 |
21İzleyin | CVE-2022-2534İstismar yok | An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 15.0.5, all versions starting from 15.1 before gitlab · gitlab | Orta5,3 | — | %0,6 | 5 Ağu 2022 |
26İzleyin | CVE-2022-2512İstismar yok | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 beforegitlab · gitlab | Orta6,5 | — | %0,9 | 5 Ağu 2022 |
18İzleyin | CVE-2022-2417İstismar yok | Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 algitlab · gitlab · CWE-20 | Orta4,5 | — | %0,7 | 5 Ağu 2022 |
24İzleyin | CVE-2022-0167İstismar yok | An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting from 14.5.0 before 14.gitlab · gitlab · CWE-79 | Orta6,1 | — | %0,8 | 1 Tem 2022 |
26İzleyin | CVE-2022-2228İstismar yok | Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows agitlab · gitlab | Orta6,5 | — | %0,8 | 1 Tem 2022 |
- CVE-2022-376726İzleyin
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every
OrtaCVSS 6,5İstismar yokEPSS %1gitlab · dynamic application security testing analyzer9 Mar 2023
- CVE-2022-420626İzleyin
A sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102, exposing the Author
OrtaCVSS 6,5İstismar yokEPSS %1gitlab · dast api scanner31 Oca 2023
- CVE-2022-425521İzleyin
An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 whi
OrtaCVSS 5,3İstismar yokEPSS %0gitlab · gitlab27 Oca 2023
- CVE-2022-420530İzleyin
In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash.
YüksekCVSS 7,5İstismar yokEPSS %1gitlab · gitlab27 Oca 2023
- CVE-2022-420121İzleyin
A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to c
OrtaCVSS 5,3İstismar yokEPSS %1gitlab · gitlab27 Oca 2023
- CVE-2022-382026İzleyin
An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2.
OrtaCVSS 6,5İstismar yokEPSS %1gitlab · gitlab26 Oca 2023
- CVE-2022-381917İzleyin
An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15
OrtaCVSS 4,3İstismar yokEPSS %0gitlab · gitlab9 Kas 2022
- CVE-2022-381821İzleyin
An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, a
OrtaCVSS 5,3İstismar yokEPSS %1gitlab · gitlab9 Kas 2022
- CVE-2022-379321İzleyin
An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15
OrtaCVSS 5,3İstismar yokEPSS %1gitlab · gitlab9 Kas 2022
- CVE-2022-370617İzleyin
Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allo
OrtaCVSS 4,3İstismar yokEPSS %1gitlab · gitlab9 Kas 2022
- CVE-2022-341317İzleyin
Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4,
OrtaCVSS 4,3İstismar yokEPSS %0gitlab · gitlab9 Kas 2022
- CVE-2022-328530İzleyin
Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 a
YüksekCVSS 7,5İstismar yokEPSS %1gitlab · gitlab9 Kas 2022
- CVE-2022-301819İzleyin
An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 1
OrtaCVSS 4,9İstismar yokEPSS %1gitlab · gitlab28 Eki 2022
- CVE-2022-333017İzleyin
It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.
OrtaCVSS 4,3İstismar yokEPSS %1gitlab · gitlab17 Eki 2022
- CVE-2022-332517İzleyin
Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 bef
OrtaCVSS 4,3İstismar yokEPSS %0gitlab · gitlab17 Eki 2022
- CVE-2022-329317İzleyin
Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 pri
OrtaCVSS 4,3İstismar yokEPSS %1gitlab · gitlab17 Eki 2022
- CVE-2022-329126İzleyin
Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.
OrtaCVSS 6,5İstismar yokEPSS %1gitlab · gitlab17 Eki 2022
- CVE-2022-328621İzleyin
Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 al
OrtaCVSS 5,3İstismar yokEPSS %0gitlab · gitlab17 Eki 2022
- CVE-2022-253329İzleyin
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2
YüksekCVSS 7,4İstismar yokEPSS %1gitlab · gitlab17 Eki 2022
- CVE-2022-253921İzleyin
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.6 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior
OrtaCVSS 5,3İstismar yokEPSS %1gitlab · gitlab5 Ağu 2022
- CVE-2022-253421İzleyin
An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 15.0.5, all versions starting from 15.1 before
OrtaCVSS 5,3İstismar yokEPSS %1gitlab · gitlab5 Ağu 2022
- CVE-2022-251226İzleyin
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before
OrtaCVSS 6,5İstismar yokEPSS %1gitlab · gitlab5 Ağu 2022
- CVE-2022-241718İzleyin
Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 al
OrtaCVSS 4,5İstismar yokEPSS %1gitlab · gitlab5 Ağu 2022
- CVE-2022-016724İzleyin
An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting from 14.5.0 before 14.
OrtaCVSS 6,1İstismar yokEPSS %1gitlab · gitlab1 Tem 2022
- CVE-2022-222826İzleyin
Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a
OrtaCVSS 6,5İstismar yokEPSS %1gitlab · gitlab1 Tem 2022