Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2022-2243

около 4 лет назад

An access control vulnerability in GitLab EE/CE affecting all versions ...

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2022-2243

около 4 лет назад

An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.

CVSS3: 5
EPSS: Низкий
debian логотип

CVE-2022-2235

около 4 лет назад

Insufficient sanitization in GitLab EE's external issue tracker affect ...

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2022-2235

около 4 лет назад

Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2022-2230

около 4 лет назад

A Stored Cross-Site Scripting vulnerability in the project settings pa ...

CVSS3: 8.1
EPSS: Средний
nvd логотип

CVE-2022-2230

около 4 лет назад

A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

CVSS3: 8.1
EPSS: Средний
debian логотип

CVE-2022-2227

около 4 лет назад

Improper access control in the runner jobs API in GitLab CE/EE affecti ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-2227

около 4 лет назад

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2022-2185

около 4 лет назад

A critical issue has been discovered in GitLab affecting all versions ...

CVSS3: 9.9
EPSS: Высокий
nvd логотип

CVE-2022-2185

около 4 лет назад

A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.

CVSS3: 9.9
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2022-2243

An access control vulnerability in GitLab EE/CE affecting all versions ...

CVSS3: 5
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-2243

An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.

CVSS3: 5
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-2235

Insufficient sanitization in GitLab EE's external issue tracker affect ...

CVSS3: 8.7
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-2235

Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link

CVSS3: 8.7
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-2230

A Stored Cross-Site Scripting vulnerability in the project settings pa ...

CVSS3: 8.1
56%
Средний
около 4 лет назад
nvd логотип
CVE-2022-2230

A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

CVSS3: 8.1
56%
Средний
около 4 лет назад
debian логотип
CVE-2022-2227

Improper access control in the runner jobs API in GitLab CE/EE affecti ...

CVSS3: 3.1
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-2227

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVSS3: 3.1
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-2185

A critical issue has been discovered in GitLab affecting all versions ...

CVSS3: 9.9
77%
Высокий
около 4 лет назад
nvd логотип
CVE-2022-2185

A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.

CVSS3: 9.9
77%
Высокий
около 4 лет назад

Уязвимостей на страницу


Поделиться