Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

ubuntu логотип

CVE-2023-5612

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-0456

больше 2 лет назад

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-0456

больше 2 лет назад

An authorization vulnerability exists in GitLab versions 14.0 prior to ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-0402

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

CVSS3: 9.9
EPSS: Низкий
debian логотип

CVE-2024-0402

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 9.9
EPSS: Низкий
nvd логотип

CVE-2023-5933

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2023-5933

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions af ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2024-0456

больше 2 лет назад

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-5933

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2024-0402

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

CVSS3: 9.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2023-5612

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

CVSS3: 5.3
5%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-0456

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-0456

An authorization vulnerability exists in GitLab versions 14.0 prior to ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-0402

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

CVSS3: 9.9
4%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-0402

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 9.9
4%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-5933

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

CVSS3: 6.4
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-5933

An issue has been discovered in GitLab CE/EE affecting all versions af ...

CVSS3: 6.4
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2024-0456

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-5933

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

CVSS3: 6.4
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2024-0402

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

CVSS3: 9.9
4%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться