Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2022-3820

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-3740

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-3740

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries by using Deploy tokens or Deploy keys .

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-3572

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2022-3572

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims.

CVSS3: 9.3
EPSS: Низкий
debian логотип

CVE-2022-3482

больше 3 лет назад

An improper access control issue in GitLab CE/EE affecting all version ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-3482

больше 3 лет назад

An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allowed an unauthorized user to see release names even when releases we set to be restricted to project members only

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-3478

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-3478

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible to trigger a DoS attack by uploading a malicious nuget package.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-3820

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-3820

An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3740

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3740

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries by using Deploy tokens or Deploy keys .

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3572

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 9.3
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3572

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims.

CVSS3: 9.3
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3482

An improper access control issue in GitLab CE/EE affecting all version ...

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3482

An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allowed an unauthorized user to see release names even when releases we set to be restricted to project members only

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3478

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3478

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible to trigger a DoS attack by uploading a malicious nuget package.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3820

An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться