Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2023-7028

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVSS3: 10
EPSS: Критический
debian логотип

CVE-2023-7028

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 10
EPSS: Критический
nvd логотип

CVE-2023-6955

больше 2 лет назад

A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group.

CVSS3: 6.6
EPSS: Низкий
debian логотип

CVE-2023-6955

больше 2 лет назад

A missing authorization check vulnerability exists in GitLab Remote De ...

CVSS3: 6.6
EPSS: Низкий
nvd логотип

CVE-2023-5356

больше 2 лет назад

Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2023-5356

больше 2 лет назад

Incorrect authorization checks in GitLab CE/EE from all versions start ...

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2023-4812

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2023-4812

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2023-2030

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2023-2030

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2023-7028

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVSS3: 10
95%
Критический
больше 2 лет назад
debian логотип
CVE-2023-7028

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 10
95%
Критический
больше 2 лет назад
nvd логотип
CVE-2023-6955

A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group.

CVSS3: 6.6
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-6955

A missing authorization check vulnerability exists in GitLab Remote De ...

CVSS3: 6.6
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-5356

Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.

CVSS3: 7.3
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-5356

Incorrect authorization checks in GitLab CE/EE from all versions start ...

CVSS3: 7.3
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4812

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.

CVSS3: 7.6
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-4812

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 7.6
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-2030

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-2030

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 3.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться