Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2018-17452

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2018-17452

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-17451

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-17451

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-17450

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2018-17450

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2018-17449

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-17449

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure direct object reference.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-15472

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-15472

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter using rouge can block for a long time in Sidekiq jobs without any timeout.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2018-17452

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-17452

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2018-17451

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-17451

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2018-17450

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-17450

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2018-17449

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-17449

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure direct object reference.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2018-15472

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2018-15472

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter using rouge can block for a long time in Sidekiq jobs without any timeout.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться