Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2023-4647

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-4647

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-4378

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A malicious Maintainer can, under specific circumstances, leak the sentry token by changing the configured URL in the Sentry error tracking settings page. This was as a result of an incomplete fix for CVE-2022-4365.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2023-4378

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-4018

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to create model experiments in public projects.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-4018

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-3950

почти 3 года назад

An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2023-3950

почти 3 года назад

An information disclosure issue in GitLab EE affecting all versions fr ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-3915

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-3915

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2023-4647

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.

CVSS3: 5.3
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-4647

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.3
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-4378

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A malicious Maintainer can, under specific circumstances, leak the sentry token by changing the configured URL in the Sentry error tracking settings page. This was as a result of an incomplete fix for CVE-2022-4365.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-4378

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-4018

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to create model experiments in public projects.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-4018

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-3950

An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-3950

An information disclosure issue in GitLab EE affecting all versions fr ...

CVSS3: 5.5
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-3915

An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-3915

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.5
1%
Низкий
почти 3 года назад

Уязвимостей на страницу


Поделиться