Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-xgmj-r659-f4c7

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-cjf2-62xp-p6mj

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Access tokens may have been logged when a query was made to a specific endpoint.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2023-3994

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use ProjectReferenceFilter to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-3994

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-3993

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Access tokens may have been logged when a query was made to a specific endpoint.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2023-3993

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2023-3900

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-3900

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-3500

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2023-3500

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-xgmj-r659-f4c7

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

CVSS3: 4.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-cjf2-62xp-p6mj

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Access tokens may have been logged when a query was made to a specific endpoint.

CVSS3: 4.9
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-3994

An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use ProjectReferenceFilter to the preview_markdown endpoint.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-3994

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-3993

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Access tokens may have been logged when a query was made to a specific endpoint.

CVSS3: 4.9
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-3993

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.9
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-3900

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

CVSS3: 4.3
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-3900

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-3500

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

CVSS3: 4.8
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-3500

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.8
1%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться