Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2025-2045

больше 1 года назад

Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-2045

больше 1 года назад

Improper authorization in GitLab EE affecting all versions from 17.7 p ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-6xr7-mv6q-jx4q

больше 1 года назад

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2025-1540

больше 1 года назад

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2025-1540

больше 1 года назад

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedi ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2025-1540

больше 1 года назад

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-2862-gpw6-r482

больше 1 года назад

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2025-0555

больше 1 года назад

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2025-0555

больше 1 года назад

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all ...

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-wpxf-3mm2-76f8

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2025-2045

Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2025-2045

Improper authorization in GitLab EE affecting all versions from 17.7 p ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-6xr7-mv6q-jx4q

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

CVSS3: 3.1
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-1540

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

CVSS3: 3.1
0%
Низкий
больше 1 года назад
debian логотип
CVE-2025-1540

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedi ...

CVSS3: 3.1
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-1540

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

CVSS3: 3.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2862-gpw6-r482

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.

CVSS3: 7.7
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-0555

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.

CVSS3: 7.7
0%
Низкий
больше 1 года назад
debian логотип
CVE-2025-0555

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all ...

CVSS3: 7.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-wpxf-3mm2-76f8

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.

CVSS3: 8.7
0%
Низкий
больше 1 года назад

Уязвимостей на страницу


Поделиться