Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2023-1098

больше 3 лет назад

An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configuration.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2023-0523

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2023-0523

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2023-0319

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2023-0319

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2022-3513

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2022-3513

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A specially crafted payload could lead to a reflected XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims on self-hosted instances running without strict CSP.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2022-3375

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-3375

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible to disclose the branch names when attacker has a fork of a project that was switched to private.

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2023-1733

больше 3 лет назад

A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1.

CVSS3: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2023-1098

An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configuration.

CVSS3: 5.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2023-0523

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-0523

An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2023-0319

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-0319

An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only.

CVSS3: 5.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3513

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3513

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A specially crafted payload could lead to a reflected XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims on self-hosted instances running without strict CSP.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3375

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.1
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3375

An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible to disclose the branch names when attacker has a fork of a project that was switched to private.

CVSS3: 3.1
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2023-1733

A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1.

CVSS3: 5.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться