Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2022-4037

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2022-3870

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-3870

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated users to download user avatars using the victim's user ID, on private instances that restrict public level visibility.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-3613

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2022-3613

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of Service.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2022-3573

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-3573

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-3514

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-3514

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in the submodule URL parser.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-4342

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-4037

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.

CVSS3: 6.4
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3870

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3870

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated users to download user avatars using the victim's user ID, on private instances that restrict public level visibility.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3613

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 5.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3613

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of Service.

CVSS3: 5.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3573

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3573

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3514

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3514

An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in the submodule URL parser.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-4342

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться