Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.618.718.8202520262027

Недавние уязвимости Gitlab

Количество 5 332

github логотип

GHSA-6mpj-fw9g-9wqm

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3r2c-p78w-vg88

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-p7gw-xwgf-7w7c

около 1 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to modify instance-wide AI feature provider settings by exploiting missing authorization checks in GraphQL mutations.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-jxx7-c7v6-wh2p

около 1 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces by manipulating namespace identifiers in API requests.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-w2j6-r4xj-rjcj

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user with specific permissions to remove all project runners from unrelated projects by manipulating GraphQL runner associations.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-rh5v-9jwc-7736

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to create a denial of service condition by providing crafted responses to external API calls.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-9222

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2025-9222

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2025-3950

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2025-3950

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-6mpj-fw9g-9wqm

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

CVSS3: 3.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3r2c-p78w-vg88

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

CVSS3: 8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-p7gw-xwgf-7w7c

GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to modify instance-wide AI feature provider settings by exploiting missing authorization checks in GraphQL mutations.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-jxx7-c7v6-wh2p

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces by manipulating namespace identifiers in API requests.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-w2j6-r4xj-rjcj

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user with specific permissions to remove all project runners from unrelated projects by manipulating GraphQL runner associations.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-rh5v-9jwc-7736

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to create a denial of service condition by providing crafted responses to external API calls.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-9222

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 8.7
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-9222

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.

CVSS3: 8.7
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-3950

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-3950

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

CVSS3: 3.5
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу


Поделиться