Gitlab Exploits

479 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-13694 GITLAB HIGH
Google Chrome <77.0.3865.120 - Use After Free
Use after free in WebRTC in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
by nemux
CVSS 8.8
CVE-2019-16113 GITLAB HIGH
Bludit 3.9.2 - Remote Code Execution via Image Upload Path Traversal
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.
by s0ups
CVSS 8.8
CVE-2019-17240 GITLAB CRITICAL
Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass via X-Forwarded-For Header
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.
by quizno
CVSS 9.8
CVE-2019-7609 GITLAB CRITICAL
Kibana Timelion Prototype Pollution RCE
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
by digipenguin
CVSS 10.0
CVE-2019-16278 GITLAB CRITICAL
nostromo_nhttpd <= 1.9.6 - Remote Code Execution via Directory Traversal in http_verify
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.
by Kr0ff
CVSS 9.8
CVE-2019-1069 GITLAB HIGH
Windows 10 and Windows Server - Elevation of Privilege via Task Scheduler File Operation Validation
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations.
by k44sh
CVSS 7.8
CVE-2019-1821 GITLAB HIGH
Cisco Prime Infrastructure/EPN Manager - RCE
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.
by FiveO
CVSS 8.8
CVE-2019-1653 GITLAB HIGH
Cisco RV320 and RV325 Unauthenticated Remote Code Execution
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.
by FiveO
CVSS 7.5
CVE-2019-9730 GITLAB HIGH
Synaptics Sound Device <2.29 - Privilege Escalation
Incorrect access control in the CxUtilSvc component of the Synaptics Sound Device drivers prior to version 2.29 allows a local attacker to increase access privileges to the Windows Registry via an unpublished API.
by scaery
CVSS 8.8
CVE-2019-7304 GITLAB CRITICAL
Canonical snapd <2.37.1 - Command Injection
Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.
by f4T1H21
CVSS 9.8
CVE-2019-18873 GITLAB CRITICAL
FUDForum 3.0.9 - Stored Cross-Site Scripting and Remote Code Execution via User-Agent Header
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin visits user information under "User Manager" in the control panel, the payload will execute. This will allow for PHP files to be written to the web root, and for code to execute on the remote server. The problem is in admsession.php and admuser.php.
by fuzzlove-group
CVSS 9.0
CVE-2019-18839 GITLAB CRITICAL
FUDForum 3.0.9 - Stored Cross-Site Scripting and Remote Code Execution via nlogin Parameter
FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits the user information, the payload will execute. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.
by fuzzlove-group
CVSS 9.0
CVE-2019-12185 GITLAB HIGH
elabftw 1.8.5 - Authenticated Arbitrary File Upload via EntityController
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command execution. An attacker can use a user account to fully compromise the system using a POST request. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.
by fuzzlove-group
CVSS 8.8
CVE-2019-12169 GITLAB HIGH
ATutor 2.2.1-2.2.4 - Path Traversal and Arbitrary File Upload via Language Import ZIP Archive
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/languages/language_import.php (aka Import New Language) or mods/_standard/patcher/index_admin.php (aka Patcher) component.
by fuzzlove-group
CVSS 8.8
CVE-2019-12170 GITLAB HIGH
ATutor <= 2.2.4 - Authenticated Arbitrary File Upload via Backup ZIP Archive
ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This may result in remote command execution. An attacker can use the instructor account to fully compromise the system using a crafted backup ZIP archive. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.
by fuzzlove-group
CVSS 8.8
CVE-2019-19492 GITLAB CRITICAL
FreeSWITCH <1.10.1 - Info Disclosure
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
by mdelaclaire
CVSS 9.8
CVE-2019-11932 GITLAB HIGH
WhatsApp < 2.19.244 - Remote Code Execution via GIF Image Parsing
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.
by mdelaclaire
CVSS 8.8
CVE-2019-5736 GITLAB HIGH
Docker Container Escape Via runC Overwrite
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
by sastraadiwiguna-purpleeliteteaming
CVSS 8.6
CVE-2018-8072 GITLAB HIGH
EDIMAX IC-3140W < 3.06, IC-5150W < 3.09, IC-6220DC < 3.06 - Stack Overflow via getsysyeminfo.cgi
An issue was discovered on EDIMAX IC-3140W through 3.06, IC-5150W through 3.09, and IC-6220DC through 3.06 devices. The ipcam_cgi binary contains a stack-based buffer overflow that is possible to trigger from a remote unauthenticated /camera-cgi/public/getsysyeminfo.cgi?action=VALUE_HERE HTTP request: if the VALUE_HERE length is more than 0x400 (1024), it is possible to overwrite other values located on the stack due to an incorrect use of the strcpy() function.
by nemux
1 stars
CVSS 8.8
CVE-2018-7248 GITLAB MEDIUM
Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317 - Info Disclosure
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not.
by e-sterling
1 stars
CVSS 5.3
CVE-2018-0492 GITLAB HIGH
beep < 1.3.4 - Local Privilege Escalation via Race Condition
Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.
by Creased
1 stars
CVSS 7.0
CVE-2018-11233 GITLAB HIGH
Canonical Ubuntu Linux < 2.13.6 - Out-of-Bounds Read
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.
by 0xBADCA7
CVSS 7.5
CVE-2018-11233 GITLAB HIGH
Canonical Ubuntu Linux < 2.13.6 - Out-of-Bounds Read
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.
by 0xBADCA7
CVSS 7.5
CVE-2018-7600 GITLAB CRITICAL
Drupal Drupalgeddon 2 Forms API Property Injection
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
by SeppPenner
CVSS 9.8
CVE-2018-0492 GITLAB HIGH
beep < 1.3.4 - Local Privilege Escalation via Race Condition
Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.
by hackernix
CVSS 7.0