Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2024-7047

около 2 лет назад

A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2024-7047

около 2 лет назад

A cross site scripting vulnerability exists in GitLab CE/EE affecting ...

CVSS3: 7.7
EPSS: Низкий
ubuntu логотип

CVE-2024-7057

около 2 лет назад

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-h8h7-r99g-m28c

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-pqgh-rchr-9hg3

около 2 лет назад

An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-9jp8-rx43-82gm

около 2 лет назад

A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-q2f3-hg8j-4wcc

около 2 лет назад

An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2024-7091

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.

CVSS3: 4.1
EPSS: Низкий
debian логотип

CVE-2024-7091

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.1
EPSS: Низкий
nvd логотип

CVE-2024-7060

около 2 лет назад

An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.

CVSS3: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-7047

A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user.

CVSS3: 7.7
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-7047

A cross site scripting vulnerability exists in GitLab CE/EE affecting ...

CVSS3: 7.7
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-7057

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-h8h7-r99g-m28c

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.

CVSS3: 4.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-pqgh-rchr-9hg3

An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.

CVSS3: 2.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-9jp8-rx43-82gm

A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits.

CVSS3: 2.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-q2f3-hg8j-4wcc

An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles.

CVSS3: 4.4
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-7091

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.

CVSS3: 4.1
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-7091

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.1
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-7060

An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.

CVSS3: 2.6
0%
Низкий
около 2 лет назад

Уязвимостей на страницу


Поделиться