Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

ubuntu логотип

CVE-2019-14944

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-14942

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages (which have access control) could be sent over cleartext HTTP.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2018-17536

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-17536

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the merge request page via project import.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-17455

больше 3 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11 ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-17455

больше 3 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-17454

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-17454

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the issue details screen.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-17453

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2018-17453

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2019-14944

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution.

CVSS3: 6.5
2%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2019-14942

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages (which have access control) could be sent over cleartext HTTP.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2018-17536

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-17536

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the merge request page via project import.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2018-17455

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11 ...

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-17455

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2018-17454

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-17454

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the issue details screen.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2018-17453

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-17453

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться