Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2022-1948

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2022-1948

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2022-1948

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-qhmc-hgm8-7h94

около 4 лет назад

An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-q874-xrmj-fh8q

около 4 лет назад

A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

CVSS3: 4.8
EPSS: Средний
github логотип

GHSA-294h-9fqc-xfq7

около 4 лет назад

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-9wfx-xq2g-33pv

около 4 лет назад

An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-mxgw-4fpv-6f32

около 4 лет назад

Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4wc6-q22j-fx9w

около 4 лет назад

An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows project memebers with reporter role to manage issues in project's error tracking feature.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-jg7h-cr7w-5fc6

около 4 лет назад

An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2022-1948

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 8.7
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1948

An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

CVSS3: 8.7
1%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1948

An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

CVSS3: 8.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-qhmc-hgm8-7h94

An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-q874-xrmj-fh8q

A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

CVSS3: 4.8
56%
Средний
около 4 лет назад
github логотип
GHSA-294h-9fqc-xfq7

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-9wfx-xq2g-33pv

An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-mxgw-4fpv-6f32

Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-4wc6-q22j-fx9w

An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows project memebers with reporter role to manage issues in project's error tracking feature.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-jg7h-cr7w-5fc6

An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.

CVSS3: 4.3
1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться