Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
CVE-2024-8640
An issue has been discovered in GitLab EE affecting all versions start ...
CVE-2024-8635
A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL
CVE-2024-8635
A server-side request forgery issue has been discovered in GitLab EE a ...
CVE-2024-8631
A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles.
CVE-2024-8631
A privilege escalation issue has been discovered in GitLab EE affectin ...
CVE-2024-8124
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a specific POST request.
CVE-2024-8124
An issue was discovered in GitLab CE/EE affecting all versions startin ...
CVE-2024-6446
An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.3 prior to 17.3.2. A crafted URL could be used to trick a victim to trust an attacker controlled application.
CVE-2024-6446
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2024-6389
An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a guest user was able to access commit information via the release Atom endpoint, contrary to permissions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-8640 An issue has been discovered in GitLab EE affecting all versions start ... | CVSS3: 8.5 | 1% Низкий | почти 2 года назад | |
CVE-2024-8635 A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL | CVSS3: 7.7 | 1% Низкий | почти 2 года назад | |
CVE-2024-8635 A server-side request forgery issue has been discovered in GitLab EE a ... | CVSS3: 7.7 | 1% Низкий | почти 2 года назад | |
CVE-2024-8631 A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles. | CVSS3: 5.5 | 1% Низкий | почти 2 года назад | |
CVE-2024-8631 A privilege escalation issue has been discovered in GitLab EE affectin ... | CVSS3: 5.5 | 1% Низкий | почти 2 года назад | |
CVE-2024-8124 An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a specific POST request. | CVSS3: 7.5 | 40% Средний | почти 2 года назад | |
CVE-2024-8124 An issue was discovered in GitLab CE/EE affecting all versions startin ... | CVSS3: 7.5 | 40% Средний | почти 2 года назад | |
CVE-2024-6446 An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.3 prior to 17.3.2. A crafted URL could be used to trick a victim to trust an attacker controlled application. | CVSS3: 3.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-6446 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 3.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-6389 An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a guest user was able to access commit information via the release Atom endpoint, contrary to permissions. | CVSS3: 4.3 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу