Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2022-4462

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2022-4462

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response.

CVSS3: 5
EPSS: Низкий
ubuntu логотип

CVE-2023-0483

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by modifying the site.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2022-4462

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response.

CVSS3: 5
EPSS: Низкий
ubuntu логотип

CVE-2023-1084

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted request.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-q7hv-qq3g-4grg

больше 3 лет назад

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2022-4007

больше 3 лет назад

A issue has been discovered in GitLab CE/EE affecting all versions fro ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-4007

больше 3 лет назад

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2022-4007

больше 3 лет назад

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2023-01968

больше 3 лет назад

Уязвимость службы Datadog программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2022-4462

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-4462

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response.

CVSS3: 5
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2023-0483

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by modifying the site.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-4462

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response.

CVSS3: 5
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2023-1084

An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted request.

CVSS3: 2.7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-q7hv-qq3g-4grg

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-4007

A issue has been discovered in GitLab CE/EE affecting all versions fro ...

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-4007

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-4007

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2023-01968

Уязвимость службы Datadog программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 5.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться