Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2023-5207

почти 3 года назад

A vulnerability was discovered in GitLab CE and EE affecting all versi ...

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2023-5207

почти 3 года назад

A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2023-5207

почти 3 года назад

A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

CVSS3: 8.2
EPSS: Низкий
fstec логотип

BDU:2023-06328

почти 3 года назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с недостатками контроля доступа, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-v9r7-fcc3-gg2v

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-5h2j-25xj-vggw

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page.

CVSS3: 3
EPSS: Низкий
github логотип

GHSA-6f6c-487w-2449

почти 3 года назад

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-x2v6-6q9m-6qx9

почти 3 года назад

An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-qw5x-x275-9wwh

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-8f5w-v7hr-cxv5

почти 3 года назад

An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-5207

A vulnerability was discovered in GitLab CE and EE affecting all versi ...

CVSS3: 8.2
1%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-5207

A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

CVSS3: 8.2
1%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-5207

A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

CVSS3: 8.2
1%
Низкий
почти 3 года назад
fstec логотип
BDU:2023-06328

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с недостатками контроля доступа, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-v9r7-fcc3-gg2v

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-5h2j-25xj-vggw

An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page.

CVSS3: 3
0%
Низкий
почти 3 года назад
github логотип
GHSA-6f6c-487w-2449

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-x2v6-6q9m-6qx9

An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.

CVSS3: 3.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-qw5x-x275-9wwh

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-8f5w-v7hr-cxv5

An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.

CVSS3: 4.3
0%
Низкий
почти 3 года назад

Уязвимостей на страницу


Поделиться