Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

ubuntu логотип

CVE-2024-7554

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request was made in a specific manner.

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2024-5423

около 2 лет назад

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-3035

около 2 лет назад

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2024-3958

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2024-2800

около 2 лет назад

ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of service via Regex backtracking.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-3114

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the server.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-6329

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2024-6329

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2024-4784

около 2 лет назад

An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassing the password re-entry requirement to approve a policy.

CVSS3: 4.2
EPSS: Низкий
debian логотип

CVE-2024-4784

около 2 лет назад

An issue was discovered in GitLab EE starting from version 16.7 before ...

CVSS3: 4.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2024-7554

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request was made in a specific manner.

CVSS3: 4.9
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-5423

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-3035

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.

CVSS3: 6.8
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-3958

An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-2800

ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of service via Regex backtracking.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-3114

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the server.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-6329

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.

CVSS3: 5.7
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-6329

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 5.7
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-4784

An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassing the password re-entry requirement to approve a policy.

CVSS3: 4.2
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-4784

An issue was discovered in GitLab EE starting from version 16.7 before ...

CVSS3: 4.2
0%
Низкий
около 2 лет назад

Уязвимостей на страницу


Поделиться