Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
GHSA-gchc-78gm-5379
Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab
CVE-2022-3819
An improper authorization issue in GitLab CE/EE affecting all versions ...
CVE-2022-3819
An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a malicious users to set emojis on internal notes they don't have access to.
CVE-2022-3818
An uncontrolled resource consumption issue when parsing URLs in GitLab ...
CVE-2022-3818
An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance.
CVE-2022-3793
An improper authorization issue in GitLab CE/EE affecting all versions ...
CVE-2022-3793
An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they don't have access to.
CVE-2022-3726
Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all ...
CVE-2022-3726
Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.
CVE-2022-3706
Improper authorization in GitLab CE/EE affecting all versions from 7.1 ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-gchc-78gm-5379 Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
CVE-2022-3819 An improper authorization issue in GitLab CE/EE affecting all versions ... | CVSS3: 3.5 | 0% Низкий | почти 4 года назад | |
CVE-2022-3819 An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a malicious users to set emojis on internal notes they don't have access to. | CVSS3: 3.5 | 0% Низкий | почти 4 года назад | |
CVE-2022-3818 An uncontrolled resource consumption issue when parsing URLs in GitLab ... | CVSS3: 5.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-3818 An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance. | CVSS3: 5.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-3793 An improper authorization issue in GitLab CE/EE affecting all versions ... | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-3793 An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they don't have access to. | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-3726 Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all ... | CVSS3: 4.8 | 1% Низкий | почти 4 года назад | |
CVE-2022-3726 Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account. | CVSS3: 4.8 | 1% Низкий | почти 4 года назад | |
CVE-2022-3706 Improper authorization in GitLab CE/EE affecting all versions from 7.1 ... | CVSS3: 3.1 | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу