Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-8mrc-cw5j-72jw

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-5rfm-2gcw-59ww

почти 3 года назад

An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-wrm3-h327-j8wh

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD variables using the custom project templates.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xh7q-hg94-4g3m

почти 3 года назад

An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job processor.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-5963

почти 3 года назад

An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2023-5963

почти 3 года назад

An issue has been discovered in GitLab EE with Advanced Search affecti ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2023-3909

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-3909

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-3399

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD variables using the custom project templates.

CVSS3: 8.5
EPSS: Низкий
debian логотип

CVE-2023-3399

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-8mrc-cw5j-72jw

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.

CVSS3: 4.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-5rfm-2gcw-59ww

An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.

CVSS3: 3.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-wrm3-h327-j8wh

An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD variables using the custom project templates.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xh7q-hg94-4g3m

An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job processor.

CVSS3: 4.3
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-5963

An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.

CVSS3: 3.1
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-5963

An issue has been discovered in GitLab EE with Advanced Search affecti ...

CVSS3: 3.1
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-3909

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.

CVSS3: 4.3
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-3909

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-3399

An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD variables using the custom project templates.

CVSS3: 8.5
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-3399

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу


Поделиться