Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2024-6323

около 2 лет назад

Improper authorization in global search in GitLab EE affecting all ver ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-5655

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
EPSS: Низкий
debian логотип

CVE-2024-5655

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2024-5430

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2024-5430

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2024-4901

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.

CVSS3: 8.7
EPSS: Средний
debian логотип

CVE-2024-4901

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 8.7
EPSS: Средний
nvd логотип

CVE-2024-4557

около 2 лет назад

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-4557

около 2 лет назад

Multiple Denial of Service (DoS) conditions has been discovered in Git ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-4011

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2024-6323

Improper authorization in global search in GitLab EE affecting all ver ...

CVSS3: 7.5
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-5655

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
7%
Низкий
около 2 лет назад
debian логотип
CVE-2024-5655

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 9.6
7%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-5430

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.

CVSS3: 6.8
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-5430

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 6.8
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-4901

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.

CVSS3: 8.7
33%
Средний
около 2 лет назад
debian логотип
CVE-2024-4901

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 8.7
33%
Средний
около 2 лет назад
nvd логотип
CVE-2024-4557

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
debian логотип
CVE-2024-4557

Multiple Denial of Service (DoS) conditions has been discovered in Git ...

CVSS3: 6.5
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-4011

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.

CVSS3: 3.1
0%
Низкий
около 2 лет назад

Уязвимостей на страницу


Поделиться