Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-8w2x-795m-pv4v

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A specially crafted payload could lead to a reflected XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims on self-hosted instances running without strict CSP.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-f6r3-7fw8-rpcg

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-qgpv-xwh3-9v79

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-34fg-2j3p-288g

больше 3 лет назад

An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configuration.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-jc5r-hf66-vmm4

больше 3 лет назад

A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-c3qm-r5gp-mgpm

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible to disclose the branch names when attacker has a fork of a project that was switched to private.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-g8xq-pp9p-qgx8

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. It was possible to add a branch with an ambiguous name that could be used to social engineer users.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-xg8m-4qxg-vm4m

больше 3 лет назад

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-phjw-j3fx-vxpj

больше 3 лет назад

An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-7g53-7whp-2hm3

больше 3 лет назад

Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-8w2x-795m-pv4v

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A specially crafted payload could lead to a reflected XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims on self-hosted instances running without strict CSP.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-f6r3-7fw8-rpcg

An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-qgpv-xwh3-9v79

An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-34fg-2j3p-288g

An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configuration.

CVSS3: 4.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-jc5r-hf66-vmm4

A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-c3qm-r5gp-mgpm

An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible to disclose the branch names when attacker has a fork of a project that was switched to private.

CVSS3: 3.7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-g8xq-pp9p-qgx8

An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. It was possible to add a branch with an ambiguous name that could be used to social engineer users.

CVSS3: 4.6
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xg8m-4qxg-vm4m

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

CVSS3: 3.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-phjw-j3fx-vxpj

An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-7g53-7whp-2hm3

Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться