Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
CVE-2023-1417
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2023-1417
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group.
CVE-2023-1167
Improper authorization in Gitlab EE affecting all versions from 12.3.0 ...
CVE-2023-1167
Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.
CVE-2023-1071
An issue has been discovered in GitLab affecting all versions from 15. ...
CVE-2023-1071
An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic.
CVE-2023-0838
An issue has been discovered in GitLab affecting versions starting fro ...
CVE-2023-0838
An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.
CVE-2023-0450
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2023-0450
An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. It was possible to add a branch with an ambiguous name that could be used to social engineer users.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2023-1417 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 4.3 | 1% Низкий | больше 3 лет назад | |
CVE-2023-1417 An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group. | CVSS3: 4.3 | 1% Низкий | больше 3 лет назад | |
CVE-2023-1167 Improper authorization in Gitlab EE affecting all versions from 12.3.0 ... | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
CVE-2023-1167 Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR. | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
CVE-2023-1071 An issue has been discovered in GitLab affecting all versions from 15. ... | CVSS3: 3.1 | 0% Низкий | больше 3 лет назад | |
CVE-2023-1071 An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic. | CVSS3: 3.1 | 0% Низкий | больше 3 лет назад | |
CVE-2023-0838 An issue has been discovered in GitLab affecting versions starting fro ... | CVSS3: 5.5 | 1% Низкий | больше 3 лет назад | |
CVE-2023-0838 An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342. | CVSS3: 5.5 | 1% Низкий | больше 3 лет назад | |
CVE-2023-0450 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 3.7 | 1% Низкий | больше 3 лет назад | |
CVE-2023-0450 An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. It was possible to add a branch with an ambiguous name that could be used to social engineer users. | CVSS3: 3.7 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу