Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
CVE-2024-5257
An issue was discovered in GitLab CE/EE affecting all versions startin ...
CVE-2024-2880
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members.
CVE-2024-2880
An issue was discovered in GitLab CE/EE affecting all versions startin ...
CVE-2024-6385
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.
CVE-2024-5470
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.
CVE-2024-2880
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members.
CVE-2024-5257
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.
BDU:2024-05179
Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с ошибками разграничения доступа, позволяющая нарушителю выполнять конвейерные задания от имени произвольного пользователя
BDU:2024-05977
Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с неконтролируемым элементом пути поиска, позволяющая нарушителю загрузить пакет NPM с конфликтующими данными пакета
BDU:2025-02297
Уязвимость сервиса GitLab Pages программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю оказать влияние на целостность данных
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-5257 An issue was discovered in GitLab CE/EE affecting all versions startin ... | CVSS3: 4.9 | 0% Низкий | около 2 лет назад | |
CVE-2024-2880 An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members. | CVSS3: 2.7 | 0% Низкий | около 2 лет назад | |
CVE-2024-2880 An issue was discovered in GitLab CE/EE affecting all versions startin ... | CVSS3: 2.7 | 0% Низкий | около 2 лет назад | |
CVE-2024-6385 An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances. | CVSS3: 9.6 | 6% Низкий | около 2 лет назад | |
CVE-2024-5470 An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens. | CVSS3: 3.8 | 0% Низкий | около 2 лет назад | |
CVE-2024-2880 An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members. | CVSS3: 2.7 | 0% Низкий | около 2 лет назад | |
CVE-2024-5257 An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace. | CVSS3: 4.9 | 0% Низкий | около 2 лет назад | |
BDU:2024-05179 Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с ошибками разграничения доступа, позволяющая нарушителю выполнять конвейерные задания от имени произвольного пользователя | CVSS3: 9.6 | 6% Низкий | около 2 лет назад | |
BDU:2024-05977 Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с неконтролируемым элементом пути поиска, позволяющая нарушителю загрузить пакет NPM с конфликтующими данными пакета | CVSS3: 3 | 0% Низкий | около 2 лет назад | |
BDU:2025-02297 Уязвимость сервиса GitLab Pages программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю оказать влияние на целостность данных | CVSS3: 3.5 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу