Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 920

debian логотип

CVE-2024-4025

около 1 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/E ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-4994

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutations.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2024-4025

около 1 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-5121

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.

CVSS3: 8.5
EPSS: Низкий
debian логотип

CVE-2025-5121

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2025-2443

около 1 года назад

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2025-2443

около 1 года назад

An issue has been discovered in GitLab EE that allows for cross-site-s ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2025-2443

около 1 года назад

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2025-5121

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-wcpq-3gmh-2fh6

около 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials.

CVSS3: 4.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2024-4025

A Denial of Service (DoS) condition has been discovered in GitLab CE/E ...

CVSS3: 6.5
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-4994

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutations.

CVSS3: 8.1
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-4025

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.

CVSS3: 6.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-5121

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.

CVSS3: 8.5
10%
Низкий
около 1 года назад
debian логотип
CVE-2025-5121

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.5
10%
Низкий
около 1 года назад
nvd логотип
CVE-2025-2443

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 8.7
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-2443

An issue has been discovered in GitLab EE that allows for cross-site-s ...

CVSS3: 8.7
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-2443

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 8.7
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-5121

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.

CVSS3: 8.5
10%
Низкий
около 1 года назад
github логотип
GHSA-wcpq-3gmh-2fh6

An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials.

CVSS3: 4.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу


Поделиться