Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
CVE-2022-3060
Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests
CVE-2022-3031
An issue has been discovered in GitLab CE/EE affecting all versions be ...
CVE-2022-3031
An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted requests to a specific endpoint, even if the victim user has 2FA enabled on their account.
CVE-2022-3030
An improper access control issue in GitLab CE/EE affecting all version ...
CVE-2022-3030
An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.
CVE-2022-2992
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prio ...
CVE-2022-2992
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.
CVE-2022-2931
A potential DOS vulnerability was discovered in GitLab CE/EE affecting ...
CVE-2022-2931
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.
CVE-2022-2908
A potential DoS vulnerability was discovered in Gitlab CE/EE versions ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2022-3060 Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests | CVSS3: 7.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-3031 An issue has been discovered in GitLab CE/EE affecting all versions be ... | CVSS3: 3.7 | 1% Низкий | почти 4 года назад | |
CVE-2022-3031 An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted requests to a specific endpoint, even if the victim user has 2FA enabled on their account. | CVSS3: 3.7 | 1% Низкий | почти 4 года назад | |
CVE-2022-3030 An improper access control issue in GitLab CE/EE affecting all version ... | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-3030 An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users. | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-2992 A vulnerability in GitLab CE/EE affecting all versions from 11.10 prio ... | CVSS3: 9.9 | 86% Высокий | почти 4 года назад | |
CVE-2022-2992 A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint. | CVSS3: 9.9 | 86% Высокий | почти 4 года назад | |
CVE-2022-2931 A potential DOS vulnerability was discovered in GitLab CE/EE affecting ... | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
CVE-2022-2931 A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
CVE-2022-2908 A potential DoS vulnerability was discovered in Gitlab CE/EE versions ... | CVSS3: 4.3 | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу