Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
CVE-2023-0042
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.
CVE-2022-4365
An issue has been discovered in GitLab CE/EE affecting all versions st ...
CVE-2022-4365
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by changing the configured URL in the Sentry error tracking settings page.
CVE-2022-4342
An issue has been discovered in GitLab CE/EE affecting all versions st ...
CVE-2022-4342
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook.
CVE-2022-4167
Incorrect Authorization check affecting all versions of GitLab EE from ...
CVE-2022-4167
Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.
CVE-2022-4131
An issue has been discovered in GitLab CE/EE affecting all versions st ...
CVE-2022-4131
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in how the application parses user agents.
CVE-2022-4037
An issue has been discovered in GitLab CE/EE affecting all versions be ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2023-0042 An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
CVE-2022-4365 An issue has been discovered in GitLab CE/EE affecting all versions st ... | CVSS3: 5.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-4365 An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by changing the configured URL in the Sentry error tracking settings page. | CVSS3: 5.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-4342 An issue has been discovered in GitLab CE/EE affecting all versions st ... | CVSS3: 5.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-4342 An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook. | CVSS3: 5.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-4167 Incorrect Authorization check affecting all versions of GitLab EE from ... | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
CVE-2022-4167 Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them. | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
CVE-2022-4131 An issue has been discovered in GitLab CE/EE affecting all versions st ... | CVSS3: 4.3 | 1% Низкий | больше 3 лет назад | |
CVE-2022-4131 An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in how the application parses user agents. | CVSS3: 4.3 | 1% Низкий | больше 3 лет назад | |
CVE-2022-4037 An issue has been discovered in GitLab CE/EE affecting all versions be ... | CVSS3: 6.4 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу