Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2022-2533

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-2527

почти 4 года назад

An issue in Incident Timelines has been discovered in GitLab CE/EE aff ...

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2022-2527

почти 4 года назад

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2022-2455

почти 4 года назад

A business logic issue in the handling of large repositories in all ve ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-2455

почти 4 года назад

A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an authenticated and authorized user to exhaust server resources by importing a malicious project.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-2428

почти 4 года назад

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting ...

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2022-2428

почти 4 года назад

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2022-3293

почти 4 года назад

Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-3279

почти 4 года назад

An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2022-3030

почти 4 года назад

An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-2533

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2527

An issue in Incident Timelines has been discovered in GitLab CE/EE aff ...

CVSS3: 7.3
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2527

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

CVSS3: 7.3
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2455

A business logic issue in the handling of large repositories in all ve ...

CVSS3: 6.5
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2455

A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an authenticated and authorized user to exhaust server resources by importing a malicious project.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2428

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting ...

CVSS3: 6.4
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2428

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests

CVSS3: 6.4
1%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-3293

Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

CVSS3: 3.5
1%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-3279

An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs

CVSS3: 2.7
1%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-3030

An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.

CVSS3: 4.3
1%
Низкий
почти 4 года назад

Уязвимостей на страницу


Поделиться