Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2022-2228

около 4 лет назад

Information exposure in GitLab EE affecting all versions from 12.0 pri ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-2228

около 4 лет назад

Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner is calling from outside the allowed IP range

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-1999

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-1999

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. Under certain conditions, using the REST API an unprivileged user was able to change labels description.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2022-1981

около 4 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2022-1981

около 4 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that allow-list may be bypassed if a Maintainer uses the 'Invite a group' feature to invite a group that has members that don't comply with domain allow-list.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2022-1963

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-1963

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab reveals if a user has enabled two-factor authentication on their account in the HTML source, to unauthenticated users.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-2270

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-1963

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab reveals if a user has enabled two-factor authentication on their account in the HTML source, to unauthenticated users.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2022-2228

Information exposure in GitLab EE affecting all versions from 12.0 pri ...

CVSS3: 5.3
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-2228

Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner is calling from outside the allowed IP range

CVSS3: 5.3
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1999

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 3.1
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1999

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. Under certain conditions, using the REST API an unprivileged user was able to change labels description.

CVSS3: 3.1
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1981

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 2.7
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1981

An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that allow-list may be bypassed if a Maintainer uses the 'Invite a group' feature to invite a group that has members that don't comply with domain allow-list.

CVSS3: 2.7
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1963

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1963

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab reveals if a user has enabled two-factor authentication on their account in the HTML source, to unauthenticated users.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-2270

An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.

CVSS3: 3.5
1%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1963

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab reveals if a user has enabled two-factor authentication on their account in the HTML source, to unauthenticated users.

CVSS3: 5.3
1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться