Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 920

ubuntu логотип

CVE-2024-12093

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2025-0605

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2025-4979

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2025-4979

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2025-3111

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service..

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-3111

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-2853

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-2853

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-1110

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2025-1110

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2024-12093

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

CVSS3: 6.8
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-0605

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

CVSS3: 4.6
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-4979

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.

CVSS3: 4.9
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-4979

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 4.9
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-3111

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service..

CVSS3: 6.5
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-3111

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-2853

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition.

CVSS3: 6.5
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-2853

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 6.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-1110

An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.

CVSS3: 2.7
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-1110

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 2.7
0%
Низкий
около 1 года назад

Уязвимостей на страницу


Поделиться