Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
CVE-2022-2908
A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a special crafted input added in the Commit message field.
CVE-2022-2884
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 pri ...
CVE-2022-2884
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint
CVE-2022-2865
A cross-site scripting issue has been discovered in GitLab CE/EE affec ...
CVE-2022-2865
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.
CVE-2022-2630
An improper access control issue in GitLab CE/EE affecting all version ...
CVE-2022-2630
An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events.
CVE-2022-2592
A lack of length validation in Snippet descriptions in GitLab CE/EE af ...
CVE-2022-2592
A lack of length validation in Snippet descriptions in GitLab CE/EE affecting all versions prior to 15.1.6, 15.2 prior to 15.2.4 and 15.3 prior to 15.3.2 allows an authenticated attacker to create a maliciously large Snippet which when requested with or without authentication places excessive load on the server, potential leading to Denial of Service.
CVE-2022-2533
An issue has been discovered in GitLab affecting all versions starting ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2022-2908 A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a special crafted input added in the Commit message field. | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-2884 A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 pri ... | CVSS3: 9.9 | 76% Высокий | почти 4 года назад | |
CVE-2022-2884 A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint | CVSS3: 9.9 | 76% Высокий | почти 4 года назад | |
CVE-2022-2865 A cross-site scripting issue has been discovered in GitLab CE/EE affec ... | CVSS3: 7.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-2865 A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side. | CVSS3: 7.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-2630 An improper access control issue in GitLab CE/EE affecting all version ... | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-2630 An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events. | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-2592 A lack of length validation in Snippet descriptions in GitLab CE/EE af ... | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
CVE-2022-2592 A lack of length validation in Snippet descriptions in GitLab CE/EE affecting all versions prior to 15.1.6, 15.2 prior to 15.2.4 and 15.3 prior to 15.3.2 allows an authenticated attacker to create a maliciously large Snippet which when requested with or without authentication places excessive load on the server, potential leading to Denial of Service. | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
CVE-2022-2533 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 6.5 | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу