Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2024-1525

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password using their verified secondary email address and sign-in using direct authentication with the reset password, bypassing LDAP.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-1525

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-1451

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."

CVSS3: 8.7
EPSS: Средний
debian логотип

CVE-2024-1451

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.7
EPSS: Средний
nvd логотип

CVE-2024-0861

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the `Guest` role can change `Custom dashboard projects` settings contrary to permissions.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-0861

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-0410

больше 2 лет назад

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2024-0410

больше 2 лет назад

An authorization bypass vulnerability was discovered in GitLab affecti ...

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2023-6477

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be able to make a group, other members or themselves Owners of that group, which may lead to privilege escalation.

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2023-6477

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-1525

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password using their verified secondary email address and sign-in using direct authentication with the reset password, bypassing LDAP.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-1525

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-1451

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."

CVSS3: 8.7
51%
Средний
больше 2 лет назад
debian логотип
CVE-2024-1451

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.7
51%
Средний
больше 2 лет назад
nvd логотип
CVE-2024-0861

An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the `Guest` role can change `Custom dashboard projects` settings contrary to permissions.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-0861

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-0410

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

CVSS3: 7.7
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-0410

An authorization bypass vulnerability was discovered in GitLab affecti ...

CVSS3: 7.7
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-6477

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be able to make a group, other members or themselves Owners of that group, which may lead to privilege escalation.

CVSS3: 6.7
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-6477

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.7
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться