Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2022-1954

около 4 лет назад

A Regular Expression Denial of Service vulnerability in GitLab CE/EE a ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1954

около 4 лет назад

A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to make a GitLab instance inaccessible via specially crafted web server response headers

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-0167

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-0167

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not disabling the Autocomplete attribute of fields related to sensitive information making it possible to be retrieved under certain conditions.

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2022-1954

около 4 лет назад

A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to make a GitLab instance inaccessible via specially crafted web server response headers

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-0167

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not disabling the Autocomplete attribute of fields related to sensitive information making it possible to be retrieved under certain conditions.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2022-2270

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-2270

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-2229

около 4 лет назад

An improper authorization issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-2229

около 4 лет назад

An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2022-1954

A Regular Expression Denial of Service vulnerability in GitLab CE/EE a ...

CVSS3: 4.3
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1954

A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to make a GitLab instance inaccessible via specially crafted web server response headers

CVSS3: 4.3
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0167

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.1
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0167

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not disabling the Autocomplete attribute of fields related to sensitive information making it possible to be retrieved under certain conditions.

CVSS3: 3.1
1%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1954

A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to make a GitLab instance inaccessible via specially crafted web server response headers

CVSS3: 4.3
1%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0167

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not disabling the Autocomplete attribute of fields related to sensitive information making it possible to be retrieved under certain conditions.

CVSS3: 3.1
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-2270

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.5
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-2270

An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.

CVSS3: 3.5
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-2229

An improper authorization issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.5
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-2229

An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.

CVSS3: 7.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться