Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2023-2233

почти 3 года назад

An improper authorization issue has been discovered in GitLab CE/EE af ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2023-0989

почти 3 года назад

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-0989

почти 3 года назад

An information disclosure issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-2233

почти 3 года назад

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2023-3920

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-4532

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. Users were capable of linking CI/CD jobs of private projects which they are not a member of.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-3979

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2023-3917

почти 3 года назад

Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-0989

почти 3 года назад

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2023-06346

почти 3 года назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab Enterprise Edition, связанная с недостатками контроля доступа, позволяющая нарушителю обойти одобрение владельцев кода, изменив базовую ветвь MR

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-2233

An improper authorization issue has been discovered in GitLab CE/EE af ...

CVSS3: 3.1
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-0989

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-0989

An information disclosure issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-2233

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.

CVSS3: 3.1
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-3920

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-4532

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. Users were capable of linking CI/CD jobs of private projects which they are not a member of.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-3979

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.

CVSS3: 3.1
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-3917

Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

CVSS3: 4.3
1%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-0989

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
fstec логотип
BDU:2023-06346

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab Enterprise Edition, связанная с недостатками контроля доступа, позволяющая нарушителю обойти одобрение владельцев кода, изменив базовую ветвь MR

CVSS3: 8.1
1%
Низкий
почти 3 года назад

Уязвимостей на страницу


Поделиться