Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
CVE-2024-6323
Improper authorization in global search in GitLab EE affecting all ver ...
CVE-2024-5655
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.
CVE-2024-5655
An issue was discovered in GitLab CE/EE affecting all versions startin ...
CVE-2024-5430
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.
CVE-2024-5430
An issue was discovered in GitLab CE/EE affecting all versions startin ...
CVE-2024-4901
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.
CVE-2024-4901
An issue was discovered in GitLab CE/EE affecting all versions startin ...
CVE-2024-4557
Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline.
CVE-2024-4557
Multiple Denial of Service (DoS) conditions has been discovered in Git ...
CVE-2024-4011
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-6323 Improper authorization in global search in GitLab EE affecting all ver ... | CVSS3: 7.5 | 1% Низкий | около 2 лет назад | |
CVE-2024-5655 An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances. | CVSS3: 9.6 | 7% Низкий | около 2 лет назад | |
CVE-2024-5655 An issue was discovered in GitLab CE/EE affecting all versions startin ... | CVSS3: 9.6 | 7% Низкий | около 2 лет назад | |
CVE-2024-5430 An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL. | CVSS3: 6.8 | 0% Низкий | около 2 лет назад | |
CVE-2024-5430 An issue was discovered in GitLab CE/EE affecting all versions startin ... | CVSS3: 6.8 | 0% Низкий | около 2 лет назад | |
CVE-2024-4901 An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes. | CVSS3: 8.7 | 33% Средний | около 2 лет назад | |
CVE-2024-4901 An issue was discovered in GitLab CE/EE affecting all versions startin ... | CVSS3: 8.7 | 33% Средний | около 2 лет назад | |
CVE-2024-4557 Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline. | CVSS3: 6.5 | 1% Низкий | около 2 лет назад | |
CVE-2024-4557 Multiple Denial of Service (DoS) conditions has been discovered in Git ... | CVSS3: 6.5 | 1% Низкий | около 2 лет назад | |
CVE-2024-4011 An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives. | CVSS3: 3.1 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу