Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2023-3401

около 3 лет назад

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2023-2022

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-2022

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-2022

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-3401

около 3 лет назад

An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. The main branch of a repository with a specially designed name allows an attacker to create repositories with malicious code.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4hcg-rvwm-x96m

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to spike the resource consumption resulting in DoS.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-4011

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to spike the resource consumption resulting in DoS.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-4011

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-5jfm-fvc2-73xf

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use ProjectReferenceFilter to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mr7p-gv96-xc44

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-3401

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 4.8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-2022

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge

CVSS3: 4.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-2022

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2023-2022

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge

CVSS3: 4.3
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2023-3401

An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. The main branch of a repository with a specially designed name allows an attacker to create repositories with malicious code.

CVSS3: 4.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-4hcg-rvwm-x96m

An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to spike the resource consumption resulting in DoS.

CVSS3: 4.3
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-4011

An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to spike the resource consumption resulting in DoS.

CVSS3: 4.3
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-4011

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-5jfm-fvc2-73xf

An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use ProjectReferenceFilter to the preview_markdown endpoint.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-mr7p-gv96-xc44

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

CVSS3: 4.3
1%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться