Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2022-3060

почти 4 года назад

Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2022-3031

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2022-3031

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted requests to a specific endpoint, even if the victim user has 2FA enabled on their account.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2022-3030

почти 4 года назад

An improper access control issue in GitLab CE/EE affecting all version ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-3030

почти 4 года назад

An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-2992

почти 4 года назад

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prio ...

CVSS3: 9.9
EPSS: Высокий
nvd логотип

CVE-2022-2992

почти 4 года назад

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

CVSS3: 9.9
EPSS: Высокий
debian логотип

CVE-2022-2931

почти 4 года назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-2931

почти 4 года назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-2908

почти 4 года назад

A potential DoS vulnerability was discovered in Gitlab CE/EE versions ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-3060

Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests

CVSS3: 7.3
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-3031

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 3.7
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-3031

An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted requests to a specific endpoint, even if the victim user has 2FA enabled on their account.

CVSS3: 3.7
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-3030

An improper access control issue in GitLab CE/EE affecting all version ...

CVSS3: 4.3
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-3030

An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.

CVSS3: 4.3
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2992

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prio ...

CVSS3: 9.9
86%
Высокий
почти 4 года назад
nvd логотип
CVE-2022-2992

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

CVSS3: 9.9
86%
Высокий
почти 4 года назад
debian логотип
CVE-2022-2931

A potential DOS vulnerability was discovered in GitLab CE/EE affecting ...

CVSS3: 7.5
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2931

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2908

A potential DoS vulnerability was discovered in Gitlab CE/EE versions ...

CVSS3: 4.3
1%
Низкий
почти 4 года назад

Уязвимостей на страницу


Поделиться