Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

ubuntu логотип

CVE-2024-9633

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions starting from 17.5 before 17.5.4, all versions starting from 17.6 before 17.6.2. This issue allows an attacker to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2024-8648

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-8648

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-7404

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2024-7404

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2024-8648

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-p932-x66g-q6cc

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper output encoding could lead to XSS if CSP is not enabled.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-c7xg-c3jr-78wp

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific configurations.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2024-9693

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific configurations.

CVSS3: 8.5
EPSS: Низкий
debian логотип

CVE-2024-9693

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 8.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2024-9633

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions starting from 17.5 before 17.5.4, all versions starting from 17.6 before 17.6.2. This issue allows an attacker to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks.

CVSS3: 3.1
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8648

An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8648

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.1
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-7404

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.

CVSS3: 6.8
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-7404

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 6.8
1%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-8648

An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-p932-x66g-q6cc

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper output encoding could lead to XSS if CSP is not enabled.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-c7xg-c3jr-78wp

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific configurations.

CVSS3: 8.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-9693

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific configurations.

CVSS3: 8.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-9693

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 8.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу


Поделиться