Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2023-0042

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2022-4365

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2022-4365

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by changing the configured URL in the Sentry error tracking settings page.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2022-4342

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2022-4342

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2022-4167

больше 3 лет назад

Incorrect Authorization check affecting all versions of GitLab EE from ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-4167

больше 3 лет назад

Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-4131

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-4131

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in how the application parses user agents.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-4037

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2023-0042

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-4365

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-4365

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by changing the configured URL in the Sentry error tracking settings page.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-4342

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-4342

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-4167

Incorrect Authorization check affecting all versions of GitLab EE from ...

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-4167

Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-4131

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-4131

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in how the application parses user agents.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-4037

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 6.4
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться