Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 918

github логотип

GHSA-3g8v-4f9f-5rwp

4 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of users viewing the report via specially crafted content.

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2026-5173

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-5173

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control.

CVSS3: 8.5
EPSS: Низкий
debian логотип

CVE-2026-4916

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2026-4916

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations.

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2026-4916

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations.

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2026-5173

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control.

CVSS3: 8.5
EPSS: Низкий
debian логотип

CVE-2026-4332

4 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-4332

4 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-2619

4 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-3g8v-4f9f-5rwp

GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of users viewing the report via specially crafted content.

CVSS3: 5.7
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-5173

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 8.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-5173

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control.

CVSS3: 8.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-4916

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 2.7
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-4916

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations.

CVSS3: 2.7
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-4916

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations.

CVSS3: 2.7
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-5173

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control.

CVSS3: 8.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-4332

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 5.4
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-4332

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization.

CVSS3: 5.4
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-2619

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization.

CVSS3: 4.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу


Поделиться