Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
CVE-2023-5226
An issue has been discovered in GitLab affecting all versions before 1 ...
CVE-2023-4912
An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input.
CVE-2023-4912
An issue has been discovered in GitLab EE affecting all versions start ...
CVE-2023-4658
An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.
CVE-2023-4658
An issue has been discovered in GitLab EE affecting all versions start ...
CVE-2023-4317
An issue has been discovered in GitLab affecting all versions starting from 9.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a user with the Developer role to update a pipeline schedule from an unprotected branch to a protected branch.
CVE-2023-4317
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2023-3964
An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.
CVE-2023-3964
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2023-3949
An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects' release descriptions via an atom endpoint when release access on the public was set to only project members.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2023-5226 An issue has been discovered in GitLab affecting all versions before 1 ... | CVSS3: 4.8 | 1% Низкий | больше 2 лет назад | |
CVE-2023-4912 An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input. | CVSS3: 2.6 | 1% Низкий | больше 2 лет назад | |
CVE-2023-4912 An issue has been discovered in GitLab EE affecting all versions start ... | CVSS3: 2.6 | 1% Низкий | больше 2 лет назад | |
CVE-2023-4658 An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group. | CVSS3: 3.1 | 0% Низкий | больше 2 лет назад | |
CVE-2023-4658 An issue has been discovered in GitLab EE affecting all versions start ... | CVSS3: 3.1 | 0% Низкий | больше 2 лет назад | |
CVE-2023-4317 An issue has been discovered in GitLab affecting all versions starting from 9.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a user with the Developer role to update a pipeline schedule from an unprotected branch to a protected branch. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-4317 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3964 An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3964 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3949 An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects' release descriptions via an atom endpoint when release access on the public was set to only project members. | CVSS3: 5.3 | 1% Низкий | больше 2 лет назад |
Уязвимостей на страницу