Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.618.718.8202520262027

Недавние уязвимости Gitlab

Количество 5 304

github логотип

GHSA-cpx5-2q84-prc5

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to leak sensitive information from specifically crafted merge request titles.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2jwx-73fx-pwrv

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI."

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2025-12734

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs to other users by injecting malicious HTML content into merge request titles.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2025-12734

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2025-12029

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI."

CVSS3: 8
EPSS: Низкий
debian логотип

CVE-2025-12029

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 8
EPSS: Низкий
ubuntu логотип

CVE-2025-12734

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs to other users by injecting malicious HTML content into merge request titles.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-j8j9-23cp-fr5v

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a Denial of Service condition by sending crafted API calls with large content parameters.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-j9w8-4m8f-75m4

около 2 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 13.2 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to disclose sensitive information from private projects by executing specifically crafted GraphQL queries.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fjj2-x466-w3hx

около 2 месяцев назад

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-cpx5-2q84-prc5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to leak sensitive information from specifically crafted merge request titles.

CVSS3: 3.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2jwx-73fx-pwrv

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI."

CVSS3: 8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-12734

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs to other users by injecting malicious HTML content into merge request titles.

CVSS3: 3.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-12734

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-12029

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI."

CVSS3: 8
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-12029

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 8
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2025-12734

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs to other users by injecting malicious HTML content into merge request titles.

CVSS3: 3.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-j8j9-23cp-fr5v

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a Denial of Service condition by sending crafted API calls with large content parameters.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-j9w8-4m8f-75m4

GitLab has remediated an issue in GitLab EE affecting all versions from 13.2 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to disclose sensitive information from private projects by executing specifically crafted GraphQL queries.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-fjj2-x466-w3hx

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.

CVSS3: 8.7
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу


Поделиться