Skip to content

Latest commit

 

History

History
123 lines (119 loc) · 15.3 KB

File metadata and controls

123 lines (119 loc) · 15.3 KB

Back

Top reports from GitLab program at HackerOne:

  1. Exfiltrate and mutate repository and project data through injected templated service to GitLab - 723 upvotes, $11000
  2. Git flag injection - local file overwrite to remote code execution to GitLab - 715 upvotes, $12000
  3. Stored XSS in Wiki pages to GitLab - 581 upvotes, $4500
  4. Local files could be overwritten in GitLab, leading to remote command execution to GitLab - 524 upvotes, $12000
  5. Project Template functionality can be used to copy private project data, such as repository, confidential issues, snippets, and merge requests to GitLab - 420 upvotes, $12000
  6. JSON serialization of any Project model results in all Runner tokens being exposed through Quick Actions to GitLab - 342 upvotes, $12000
  7. Bypass of GitLab CI runner slash fix in YAML validation to GitLab - 339 upvotes, $12000
  8. Attacker is able to access commit title and team member comments which are supposed to be private to GitLab - 333 upvotes, $7000
  9. Full access to internal Gitlab instances at redash.gitlab.com, dashboards.gitlab.com, prometheus.gitlab.com to GitLab - 281 upvotes, $9500
  10. Cross-site Scripting (XSS) - Stored in RDoc wiki pages to GitLab - 260 upvotes, $3500
  11. Bypass Email Verification -- Able to Access Internal Gitlab Services that use Login with Gitlab and Perform Check on email domain to GitLab - 223 upvotes, $3000
  12. Server Side Request Forgery mitigation bypass to GitLab - 213 upvotes, $3500
  13. Unauthenticated blind SSRF in OAuth Jira authorization controller to GitLab - 210 upvotes, $4000
  14. Group search leaks private MRs, code, commits to GitLab - 202 upvotes, $7000
  15. Snippet JS template allows attacker to read a user's private snippets to GitLab - 162 upvotes, $300
  16. Git flag injection leading to file overwrite and potential remote code execution to GitLab - 155 upvotes, $3500
  17. information disclosure of secret_key_base via encoding charcters to GitLab - 140 upvotes, $3500
  18. DoS on the Issue page by exploiting Mermaid. to GitLab - 135 upvotes, $3000
  19. Importing GitLab project archives can replace uploads of other users to GitLab - 132 upvotes, $5000
  20. Persistent XSS in Note objects to GitLab - 132 upvotes, $4500
  21. Git flag injection - Search API with scope 'blobs' to GitLab - 116 upvotes, $7000
  22. Read files on application server, leads to RCE to GitLab - 108 upvotes, $0
  23. Group search with Elastic search enable leaks unrelated data to GitLab - 95 upvotes, $7000
  24. DoS attack via comment on Issue to GitLab - 74 upvotes, $1000
  25. SSRF in CI after first run to GitLab - 69 upvotes, $3000
  26. GraphQL query "namespace" leaks data to GitLab - 58 upvotes, $1000
  27. Ability to access all user authentication tokens, leads to RCE to GitLab - 56 upvotes, $0
  28. Know whether private project name exists or not within a group using link comments to GitLab - 55 upvotes, $300
  29. GitLab::UrlBlocker validation bypass leading to full Server Side Request Forgery to GitLab - 52 upvotes, $5000
  30. All functions that allow users to specify color code are vulnerable to ReDoS to GitLab - 48 upvotes, $1000
  31. Clientside resource Exhausting by exploiting gitlab math rendering to GitLab - 48 upvotes, $1000
  32. Command injection by overwriting authorized_keys file through GitLab import to GitLab - 47 upvotes, $2000
  33. Bypass Email Verification using Salesforce -- Reproducible in gitlab.com to GitLab - 45 upvotes, $1500
  34. Access to GitLab's Slack by abusing issue creation from e-mail to GitLab - 45 upvotes, $0
  35. SQL injection in MilestoneFinder order method to GitLab - 38 upvotes, $2000
  36. GitLab CI runner can read and poison cache of all other projects to GitLab - 38 upvotes, $2000
  37. Milestones leaked via search API to GitLab - 38 upvotes, $1000
  38. Using GitLab to monitor and hijack domains in mass quantity. to GitLab - 33 upvotes, $750
  39. Insecure 2FA/authentication implementation creates a brute force vulnerability to GitLab - 30 upvotes, $0
  40. Bypassing push rules via MRs created by Email to GitLab - 29 upvotes, $3000
  41. Uncontrolled Resource Consumption in any Markdown field using Mermaid to GitLab - 29 upvotes, $1000
  42. Evaluating Ruby code by injecting Rescue job on the system_hook_push queue through web hook to GitLab - 29 upvotes, $750
  43. Vulnerability in project import leads to arbitrary command execution to GitLab - 29 upvotes, $0
  44. Privilege escalation due to insecure use of logrotate to GitLab - 28 upvotes, $1000
  45. Access Projects And create projects in gitlab pre production server to GitLab - 26 upvotes, $1000
  46. Mailgun misconfiguration leads to email snooping and postmaster@-access on email.mg.gitlab.com to GitLab - 25 upvotes, $0
  47. Persistent XSS via e-mail when creating merge requests to GitLab - 24 upvotes, $750
  48. Last build status and coverage leaked to unauthorized users to GitLab - 22 upvotes, $750
  49. Unauthorized users may be able to view almost all informations related to Private projects. to GitLab - 21 upvotes, $0
  50. GitLab's GitHub integration is vulnerable to SSRF vulnerability to GitLab - 20 upvotes, $2000
  51. [Markdown] Stored XSS via character encoding parser bypass to GitLab - 20 upvotes, $0
  52. Claiming package names in GitLab's automatic package referencer. to GitLab - 19 upvotes, $1000
  53. CSV injection in gitlab.com via issues export feature. to GitLab - 19 upvotes, $0
  54. Add and Access to Labels of any Private Projects/Groups of Gitlab(IDOR) to GitLab - 18 upvotes, $1000
  55. Race condition in GitLab import, giving access to other people their imports due to filename collision to GitLab - 17 upvotes, $0
  56. Stored XSS in merge request pages to GitLab - 17 upvotes, $0
  57. Stored XSS on Files overview by abusing git submodule URL to GitLab - 16 upvotes, $0
  58. all private tokens are leaked to an unauthenticated attacker to GitLab - 16 upvotes, $0
  59. Privilege escalation to access all private groups and repositories to GitLab - 15 upvotes, $0
  60. SSRF vulnerability in gitlab.com via project import. to GitLab - 15 upvotes, $0
  61. Stored XSS on Issue details page to GitLab - 14 upvotes, $0
  62. GitHub import allows user to create child group under existing namespace to GitLab - 13 upvotes, $750
  63. Bypassing password authentication of users that have 2FA enabled to GitLab - 13 upvotes, $0
  64. Persistent XSS on public wiki pages to GitLab - 13 upvotes, $0
  65. Gitlab is vulnerable to impersonation attacks due to broken links to GitLab - 13 upvotes, $0
  66. Removing a user from a private group doesn't remove him from group's project, if his project's role was changed to GitLab - 12 upvotes, $2000
  67. Private System Note Disclosure using GraphQL to GitLab - 12 upvotes, $1000
  68. Every user can delete public deploy keys to GitLab - 12 upvotes, $0
  69. Inadequate cache control in gitter allows to view private chat room to GitLab - 12 upvotes, $0
  70. State filter in IssuableFinder allows attacker to delete all issues and merge requests to GitLab - 11 upvotes, $0
  71. User with guest access can access private merge requests to GitLab - 11 upvotes, $0
  72. Unfiltered class attribute in markdown code to GitLab - 11 upvotes, $0
  73. SSRF when importing a project from a git repo by URL to GitLab - 11 upvotes, $0
  74. XSS On meta tags in profile page to GitLab - 10 upvotes, $0
  75. Users can download old project exports due to unclaimed namespace to GitLab - 10 upvotes, $0
  76. Persistent XSS - Selecting users as allowed merge request approvers to GitLab - 10 upvotes, $0
  77. HTML TAG INJECTION ON PROFILE NAME to GitLab - 10 upvotes, $0
  78. Blocked user Git access through CI/CD token to GitLab - 9 upvotes, $1500
  79. Attacker can extract list of private project's project members to GitLab - 9 upvotes, $0
  80. Head pipeline leaked to unauthorized users via blocking merge request feature to GitLab - 8 upvotes, $1000
  81. Last pipeline status for MR leaked to GitLab - 8 upvotes, $750
  82. Boards leak private label names and desciptions to GitLab - 8 upvotes, $0
  83. Users with guest access can post notes to private merge requests, issues, and snippets to GitLab - 8 upvotes, $0
  84. SSRF vulnerability in gitlab.com webhook to GitLab - 8 upvotes, $0
  85. XSS (Persistent) - Selecting role(s) for protected branches to GitLab - 8 upvotes, $0
  86. Container scanning and Dependency scanning report leaked to unauthorized users to GitLab - 7 upvotes, $3000
  87. [RDoc] XSS in project README files to GitLab - 7 upvotes, $0
  88. [reStructuredText] XSS in project README files to GitLab - 7 upvotes, $0
  89. Markdown based stored XSS (IE only) to GitLab - 7 upvotes, $0
  90. Persistent XSS - Deleting a project (No Longer Vulnerable in 10.7) to GitLab - 7 upvotes, $0
  91. Labels created in private projects are leaked to GitLab - 6 upvotes, $0
  92. Persistent XSS on public project page to GitLab - 6 upvotes, $0
  93. Gitlab.com is vulnerable to reverse tabnabbing. to GitLab - 6 upvotes, $0
  94. [Subgroups] Unprivileged User Can Disclose Private Group Names to GitLab - 6 upvotes, $0
  95. CSRF Token Bypass in Account Deletion to GitLab - 6 upvotes, $0
  96. Gitlab.com is vulnerable to reverse tabnabbing. (#2) to GitLab - 6 upvotes, $0
  97. GFM renderer leaks external issue tracker URL of private project to GitLab - 6 upvotes, $0
  98. Potensial SSRF via Git repository URL to GitLab - 6 upvotes, $0
  99. Double linking cause XSS (but blokeced by CSP in gitlab.com) to GitLab - 6 upvotes, $0
  100. Attacker can delete (and read) private project webhooks to GitLab - 5 upvotes, $0
  101. [Textile] XSS in project README files to GitLab - 5 upvotes, $0
  102. Gitlab.com is vulnerable to reverse tabnabbing via AsciiDoc links. (#3) to GitLab - 5 upvotes, $0
  103. Guests Will Disclose the Private Project Full Activity Via Project Activity Feeds to GitLab - 5 upvotes, $0
  104. Private snippets in public / internal projects leaked though GitLab API to GitLab - 4 upvotes, $0
  105. Confidential issues leaked in public projects when attached to milestone to GitLab - 4 upvotes, $0
  106. Attacker can post notes on private MR, snippets, and issues to GitLab - 4 upvotes, $0
  107. [Repository Import] Open Redirect via "continue[to]" parameter to GitLab - 4 upvotes, $0
  108. Impersonation attack via Broken Link in Resellers Page to GitLab - 4 upvotes, $0
  109. Project Milestones Disclosed Via Groups When the Victim disabled milestones access in project settings to GitLab - 3 upvotes, $1000
  110. Open redirect to GitLab - 3 upvotes, $0
  111. CSRF-Token leak by request forgery to GitLab - 3 upvotes, $0
  112. Cookie bomb to GitLab - 3 upvotes, $0
  113. SSRF via git Repo by URL Abuse to GitLab - 2 upvotes, $0
  114. Lack of validation before assigning custom domain names leading to abuse of GitLab pages service to GitLab - 2 upvotes, $0
  115. Email notification about login email changed is not received when using verified linked email address to GitLab - 2 upvotes, $0
  116. Missing/Breach of Internal Security Boundary - Access to Job Queue Results in Remote Code Execution to GitLab - 0 upvotes, $0

Back