Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

redhat логотип

CVE-2023-3500

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

EPSS: Низкий
redhat логотип

CVE-2023-0632

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

EPSS: Низкий
github логотип

GHSA-cjjr-h37f-5xw7

около 3 лет назад

An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2023-1401

около 3 лет назад

An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-5h2f-9v3w-h48r

около 3 лет назад

A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-3102

около 3 лет назад

A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-3102

около 3 лет назад

A sensitive information leak issue has been discovered in GitLab EE af ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-gqgg-x9fc-fq5c

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain situations.

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2023-3484

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain situations.

CVSS3: 8
EPSS: Низкий
debian логотип

CVE-2023-3484

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2023-3500

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

1%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-0632

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

1%
Низкий
около 3 лет назад
github логотип
GHSA-cjjr-h37f-5xw7

An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.

CVSS3: 5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-1401

An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.

CVSS3: 5
1%
Низкий
около 3 лет назад
github логотип
GHSA-5h2f-9v3w-h48r

A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR.

CVSS3: 5.3
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-3102

A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR.

CVSS3: 5.3
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-3102

A sensitive information leak issue has been discovered in GitLab EE af ...

CVSS3: 5.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-gqgg-x9fc-fq5c

An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain situations.

CVSS3: 8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-3484

An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain situations.

CVSS3: 8
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-3484

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8
1%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться