Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2022-3486

почти 4 года назад

An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2022-3483

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2022-3483

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could exfiltrate a Datadog integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2022-3285

почти 4 года назад

Bypass of healthcheck endpoint allow list affecting all versions from ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-3285

почти 4 года назад

Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-3280

почти 4 года назад

An open redirect in GitLab CE/EE affecting all versions from 10.1 prio ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-3280

почти 4 года назад

An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-3265

почти 4 года назад

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 7.3
EPSS: Высокий
nvd логотип

CVE-2022-3265

почти 4 года назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
EPSS: Высокий
debian логотип

CVE-2022-2761

почти 4 года назад

An information disclosure issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-3486

An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVSS3: 4.7
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-3483

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-3483

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could exfiltrate a Datadog integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 5.5
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-3285

Bypass of healthcheck endpoint allow list affecting all versions from ...

CVSS3: 5.3
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-3285

Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab

CVSS3: 5.3
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-3280

An open redirect in GitLab CE/EE affecting all versions from 10.1 prio ...

CVSS3: 3.5
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-3280

An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.

CVSS3: 3.5
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-3265

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 7.3
86%
Высокий
почти 4 года назад
nvd логотип
CVE-2022-3265

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
86%
Высокий
почти 4 года назад
debian логотип
CVE-2022-2761

An information disclosure issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
1%
Низкий
почти 4 года назад

Уязвимостей на страницу


Поделиться