Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2024-3958

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-3958

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-3114

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the server.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-3114

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-3035

около 2 лет назад

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2024-3035

около 2 лет назад

A permission check vulnerability in GitLab CE/EE affecting all version ...

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2024-2800

около 2 лет назад

ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of service via Regex backtracking.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-2800

около 2 лет назад

ReDoS flaw in RefMatcher when matching branch names using wildcards in ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-7610

около 2 лет назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause catastrophic backtracking while parsing results from Elasticsearch.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-4207

около 2 лет назад

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-3958

An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-3958

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 5.3
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-3114

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the server.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-3114

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.3
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-3035

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.

CVSS3: 6.8
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-3035

A permission check vulnerability in GitLab CE/EE affecting all version ...

CVSS3: 6.8
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-2800

ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of service via Regex backtracking.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
debian логотип
CVE-2024-2800

ReDoS flaw in RefMatcher when matching branch names using wildcards in ...

CVSS3: 6.5
1%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-7610

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause catastrophic backtracking while parsing results from Elasticsearch.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-4207

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVSS3: 4.4
0%
Низкий
около 2 лет назад

Уязвимостей на страницу


Поделиться