Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2022-2908

почти 4 года назад

A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a special crafted input added in the Commit message field.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-2884

почти 4 года назад

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 pri ...

CVSS3: 9.9
EPSS: Высокий
nvd логотип

CVE-2022-2884

почти 4 года назад

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

CVSS3: 9.9
EPSS: Высокий
debian логотип

CVE-2022-2865

почти 4 года назад

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2022-2865

почти 4 года назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2022-2630

почти 4 года назад

An improper access control issue in GitLab CE/EE affecting all version ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-2630

почти 4 года назад

An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-2592

почти 4 года назад

A lack of length validation in Snippet descriptions in GitLab CE/EE af ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-2592

почти 4 года назад

A lack of length validation in Snippet descriptions in GitLab CE/EE affecting all versions prior to 15.1.6, 15.2 prior to 15.2.4 and 15.3 prior to 15.3.2 allows an authenticated attacker to create a maliciously large Snippet which when requested with or without authentication places excessive load on the server, potential leading to Denial of Service.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-2533

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-2908

A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a special crafted input added in the Commit message field.

CVSS3: 4.3
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2884

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 pri ...

CVSS3: 9.9
76%
Высокий
почти 4 года назад
nvd логотип
CVE-2022-2884

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

CVSS3: 9.9
76%
Высокий
почти 4 года назад
debian логотип
CVE-2022-2865

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 7.3
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2865

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2630

An improper access control issue in GitLab CE/EE affecting all version ...

CVSS3: 4.3
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2630

An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events.

CVSS3: 4.3
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2592

A lack of length validation in Snippet descriptions in GitLab CE/EE af ...

CVSS3: 6.5
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2592

A lack of length validation in Snippet descriptions in GitLab CE/EE affecting all versions prior to 15.1.6, 15.2 prior to 15.2.4 and 15.3 prior to 15.3.2 allows an authenticated attacker to create a maliciously large Snippet which when requested with or without authentication places excessive load on the server, potential leading to Denial of Service.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2533

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
1%
Низкий
почти 4 года назад

Уязвимостей на страницу


Поделиться