Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2023-1417

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-1417

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-1167

больше 3 лет назад

Improper authorization in Gitlab EE affecting all versions from 12.3.0 ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-1167

больше 3 лет назад

Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-1071

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions from 15. ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2023-1071

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2023-0838

больше 3 лет назад

An issue has been discovered in GitLab affecting versions starting fro ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-0838

больше 3 лет назад

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2023-0450

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2023-0450

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. It was possible to add a branch with an ambiguous name that could be used to social engineer users.

CVSS3: 3.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-1417

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-1417

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2023-1167

Improper authorization in Gitlab EE affecting all versions from 12.3.0 ...

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-1167

Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2023-1071

An issue has been discovered in GitLab affecting all versions from 15. ...

CVSS3: 3.1
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-1071

An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic.

CVSS3: 3.1
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2023-0838

An issue has been discovered in GitLab affecting versions starting fro ...

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-0838

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2023-0450

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.7
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-0450

An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. It was possible to add a branch with an ambiguous name that could be used to social engineer users.

CVSS3: 3.7
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться