Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2022-1935

около 4 лет назад

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configured

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-1935

около 4 лет назад

Incorrect authorization in GitLab EE affecting all versions from 12.0 ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-1821

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for a subgroup member to access the members list of their parent group.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-1821

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1783

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for malicious group maintainers to add new members to a project within their group, through the REST API, even after their group owner enabled a setting to prevent members from being added to projects within that group.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2022-1783

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2022-1821

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for a subgroup member to access the members list of their parent group.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1935

около 4 лет назад

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configured

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-1936

около 4 лет назад

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any location even when IP address restrictions were configured

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-1944

около 4 лет назад

When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers' running jobs

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-1935

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configured

CVSS3: 6.5
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1935

Incorrect authorization in GitLab EE affecting all versions from 12.0 ...

CVSS3: 6.5
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1821

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for a subgroup member to access the members list of their parent group.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1821

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1783

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for malicious group maintainers to add new members to a project within their group, through the REST API, even after their group owner enabled a setting to prevent members from being added to projects within that group.

CVSS3: 2.7
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1783

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 2.7
1%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1821

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for a subgroup member to access the members list of their parent group.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1935

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configured

CVSS3: 6.5
1%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1936

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any location even when IP address restrictions were configured

CVSS3: 6.5
1%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1944

When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers' running jobs

CVSS3: 5.4
1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться