Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2023-5226

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2023-4912

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2023-4912

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2023-4658

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2023-4658

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2023-4317

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 9.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a user with the Developer role to update a pipeline schedule from an unprotected branch to a protected branch.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-4317

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-3964

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-3964

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-3949

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects' release descriptions via an atom endpoint when release access on the public was set to only project members.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-5226

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 4.8
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4912

An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input.

CVSS3: 2.6
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-4912

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 2.6
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4658

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-4658

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4317

An issue has been discovered in GitLab affecting all versions starting from 9.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a user with the Developer role to update a pipeline schedule from an unprotected branch to a protected branch.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-4317

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3964

An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3964

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3949

An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects' release descriptions via an atom endpoint when release access on the public was set to only project members.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться