Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-mjcr-h6w7-xcx6

почти 4 года назад

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

CVSS3: 9.9
EPSS: Высокий
github логотип

GHSA-mx6m-x365-fxj7

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-x995-4q6w-crwj

почти 4 года назад

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-hchv-vv89-9pxp

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted requests to a specific endpoint, even if the victim user has 2FA enabled on their account.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-36p7-jqv6-r5mj

почти 4 года назад

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-3351

почти 4 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-3351

почти 4 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A user's primary email may be disclosed to an attacker through group member events webhooks.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-3331

почти 4 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-3331

почти 4 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Zentao project issues.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-3330

почти 4 года назад

It was possible for a guest user to read a todo targeting an inaccessi ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-mjcr-h6w7-xcx6

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

CVSS3: 9.9
76%
Высокий
почти 4 года назад
github логотип
GHSA-mx6m-x365-fxj7

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

CVSS3: 7.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-x995-4q6w-crwj

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

CVSS3: 8
1%
Низкий
почти 4 года назад
github логотип
GHSA-hchv-vv89-9pxp

An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted requests to a specific endpoint, even if the victim user has 2FA enabled on their account.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-36p7-jqv6-r5mj

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

CVSS3: 5.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-3351

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.3
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-3351

An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A user's primary email may be disclosed to an attacker through group member events webhooks.

CVSS3: 4.3
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-3331

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.5
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-3331

An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Zentao project issues.

CVSS3: 3.5
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-3330

It was possible for a guest user to read a todo targeting an inaccessi ...

CVSS3: 4.3
1%
Низкий
почти 4 года назад

Уязвимостей на страницу


Поделиться