Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

ubuntu логотип

CVE-2024-6595

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.

CVSS3: 3
EPSS: Низкий
github логотип

GHSA-74cm-4qqj-22p4

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-xxw9-chfj-mp3c

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-c5g3-c7f9-3hcj

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-mhv3-28f9-6jvj

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.

CVSS3: 3.8
EPSS: Низкий
nvd логотип

CVE-2024-6385

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
EPSS: Низкий
debian логотип

CVE-2024-6385

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2024-5470

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.

CVSS3: 3.8
EPSS: Низкий
debian логотип

CVE-2024-5470

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 3.8
EPSS: Низкий
nvd логотип

CVE-2024-5257

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2024-6595

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.

CVSS3: 3
0%
Низкий
около 2 лет назад
github логотип
GHSA-74cm-4qqj-22p4

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
6%
Низкий
около 2 лет назад
github логотип
GHSA-xxw9-chfj-mp3c

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members.

CVSS3: 2.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-c5g3-c7f9-3hcj

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

CVSS3: 4.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-mhv3-28f9-6jvj

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.

CVSS3: 3.8
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-6385

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
6%
Низкий
около 2 лет назад
debian логотип
CVE-2024-6385

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 9.6
6%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-5470

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.

CVSS3: 3.8
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-5470

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 3.8
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-5257

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

CVSS3: 4.9
0%
Низкий
около 2 лет назад

Уязвимостей на страницу


Поделиться