Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

ubuntu логотип

CVE-2023-6477

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be able to make a group, other members or themselves Owners of that group, which may lead to privilege escalation.

CVSS3: 6.7
EPSS: Низкий
ubuntu логотип

CVE-2024-0861

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the `Guest` role can change `Custom dashboard projects` settings contrary to permissions.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-1451

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."

CVSS3: 8.7
EPSS: Средний
ubuntu логотип

CVE-2024-1525

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password using their verified secondary email address and sign-in using direct authentication with the reset password, bypassing LDAP.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2024-0410

больше 2 лет назад

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2023-3509

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2023-3509

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2023-3509

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

CVSS3: 3.7
EPSS: Низкий
fstec логотип

BDU:2024-01806

больше 2 лет назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab Enterprise Edition, связанная с недостатками контроля доступа, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2024-07893

больше 2 лет назад

Уязвимость реализации стандарта открытой авторизации (OAuth) программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю реализовать атаку Cross Window Forgery

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2023-6477

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be able to make a group, other members or themselves Owners of that group, which may lead to privilege escalation.

CVSS3: 6.7
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2024-0861

An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the `Guest` role can change `Custom dashboard projects` settings contrary to permissions.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2024-1451

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."

CVSS3: 8.7
51%
Средний
больше 2 лет назад
ubuntu логотип
CVE-2024-1525

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password using their verified secondary email address and sign-in using direct authentication with the reset password, bypassing LDAP.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2024-0410

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

CVSS3: 7.7
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3509

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

CVSS3: 3.7
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3509

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 3.7
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3509

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

CVSS3: 3.7
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-01806

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab Enterprise Edition, связанная с недостатками контроля доступа, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-07893

Уязвимость реализации стандарта открытой авторизации (OAuth) программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю реализовать атаку Cross Window Forgery

CVSS3: 6.8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться