Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.618.718.8202520262027

Недавние уязвимости Gitlab

Количество 5 268

github логотип

GHSA-pvxr-g7hw-fv88

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated users with developer access to obtain ID tokens for protected branches under certain circumstances.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-wxx2-2cv7-vhx6

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an authenticated user to cause a denial of service condition by creating specially crafted content that consumes excessive server resources when processed.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4h46-82xr-4j7x

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-qfpg-mw2p-44hg

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending specially crafted markdown payloads to the Wiki feature.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gxh9-4vgj-w44j

6 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-rwwp-3rv3-j6q6

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4vc6-9m66-j82c

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted payloads to specific integration API endpoints.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-cxxf-6583-j227

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2025-8770

6 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-8770

6 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-pvxr-g7hw-fv88

An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated users with developer access to obtain ID tokens for protected branches under certain circumstances.

CVSS3: 5
0%
Низкий
6 месяцев назад
github логотип
GHSA-wxx2-2cv7-vhx6

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an authenticated user to cause a denial of service condition by creating specially crafted content that consumes excessive server resources when processed.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-4h46-82xr-4j7x

An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.

CVSS3: 8.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-qfpg-mw2p-44hg

An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending specially crafted markdown payloads to the Wiki feature.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-gxh9-4vgj-w44j

An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-rwwp-3rv3-j6q6

An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-4vc6-9m66-j82c

An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted payloads to specific integration API endpoints.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-cxxf-6583-j227

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.

CVSS3: 6.7
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-8770

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 6.5
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-8770

An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.

CVSS3: 6.5
0%
Низкий
6 месяцев назад

Уязвимостей на страницу


Поделиться