Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2023-3424

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-3424

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-3363

около 3 лет назад

An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`.

CVSS3: 3.9
EPSS: Низкий
debian логотип

CVE-2023-3363

около 3 лет назад

An information disclosure issue in Gitlab CE/EE affecting all versions ...

CVSS3: 3.9
EPSS: Низкий
nvd логотип

CVE-2023-3362

около 3 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-3362

около 3 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-2620

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2023-2620

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-2576

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CODEOWNERS rules and merge to a protected branch.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-2576

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2023-3424

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-3424

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-3363

An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`.

CVSS3: 3.9
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-3363

An information disclosure issue in Gitlab CE/EE affecting all versions ...

CVSS3: 3.9
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-3362

An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.

CVSS3: 5.3
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-3362

An information disclosure issue in GitLab CE/EE affecting all versions ...

CVSS3: 5.3
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-2620

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838.

CVSS3: 5.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-2620

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-2576

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CODEOWNERS rules and merge to a protected branch.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-2576

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться