Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-gchc-78gm-5379

почти 4 года назад

Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-3819

почти 4 года назад

An improper authorization issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-3819

почти 4 года назад

An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a malicious users to set emojis on internal notes they don't have access to.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-3818

почти 4 года назад

An uncontrolled resource consumption issue when parsing URLs in GitLab ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-3818

почти 4 года назад

An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-3793

почти 4 года назад

An improper authorization issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-3793

почти 4 года назад

An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they don't have access to.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-3726

почти 4 года назад

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all ...

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2022-3726

почти 4 года назад

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2022-3706

почти 4 года назад

Improper authorization in GitLab CE/EE affecting all versions from 7.1 ...

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-gchc-78gm-5379

Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab

CVSS3: 7.5
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-3819

An improper authorization issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.5
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-3819

An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a malicious users to set emojis on internal notes they don't have access to.

CVSS3: 3.5
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-3818

An uncontrolled resource consumption issue when parsing URLs in GitLab ...

CVSS3: 5.3
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-3818

An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance.

CVSS3: 5.3
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-3793

An improper authorization issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-3793

An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they don't have access to.

CVSS3: 4.3
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-3726

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all ...

CVSS3: 4.8
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-3726

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.

CVSS3: 4.8
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-3706

Improper authorization in GitLab CE/EE affecting all versions from 7.1 ...

CVSS3: 3.1
1%
Низкий
почти 4 года назад

Уязвимостей на страницу


Поделиться