Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.618.718.8202520262027

Недавние уязвимости Gitlab

Количество 5 332

nvd логотип

CVE-2025-7736

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for project members by authenticating through OAuth providers.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2025-7000

3 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions f ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-7000

3 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-6945

3 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2025-6945

3 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to leak sensitive information from confidential issues by injecting hidden prompts into merge request comments.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2025-6171

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-6171

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker with reporter access to view branch names and pipeline details by accessing the packages API endpoint even when repository access was disabled.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-2615

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-2615

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-11990

3 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to gain CSRF tokens by exploiting improper input validation in repository references combined with redirect handling weaknesses.

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2025-7736

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for project members by authenticating through OAuth providers.

CVSS3: 3.1
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-7000

An issue has been discovered in GitLab CE/EE affecting all versions f ...

CVSS3: 4.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-7000

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests.

CVSS3: 4.3
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-6945

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 3.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-6945

GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to leak sensitive information from confidential issues by injecting hidden prompts into merge request comments.

CVSS3: 3.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-6171

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 5.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-6171

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker with reporter access to view branch names and pipeline details by accessing the packages API endpoint even when repository access was disabled.

CVSS3: 5.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-2615

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.

CVSS3: 4.3
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-2615

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-11990

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to gain CSRF tokens by exploiting improper input validation in repository references combined with redirect handling weaknesses.

CVSS3: 3.1
0%
Низкий
3 месяца назад

Уязвимостей на страницу


Поделиться