Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

ubuntu логотип

CVE-2022-1940

около 4 лет назад

A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues

CVSS3: 7.7
EPSS: Низкий
ubuntu логотип

CVE-2022-1783

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for malicious group maintainers to add new members to a project within their group, through the REST API, even after their group owner enabled a setting to prevent members from being added to projects within that group.

CVSS3: 2.7
EPSS: Низкий
fstec логотип

BDU:2022-03328

около 4 лет назад

Уязвимость функции SCIM (System of Cross-domain Identity Management) программной платформы на базе git для совместной работы над кодом GitLab, связанная с возможностью приглашения произвольных пользователей через свое имя пользователя и адрес электронной почты, позволяющая нарушителю выполнить захват учетных записей пользователей путем изменения адреса их электронной почты

CVSS3: 9.6
EPSS: Средний
fstec логотип

BDU:2022-03702

около 4 лет назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab Enterprise Edition, связанная с недостатками процедуры авторизации, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2022-03705

около 4 лет назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab Enterprise Edition, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный код JavaScript

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-f3cp-f6ph-xxhj

около 4 лет назад

In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s password via the change password function. There is a rate limit in place, but the attack may still be conducted by stealing the session id from the physical compromise of the account and splitting the attack over several IP addresses and passing in the compromised session value from these various locations.

EPSS: Низкий
github логотип

GHSA-h5fq-66m8-wp4v

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 1 of 5).

EPSS: Низкий
github логотип

GHSA-mv85-vhf6-fp37

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

EPSS: Низкий
github логотип

GHSA-95hp-m576-m42x

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-2244-rvc8-pc38

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.5.10, 11.6.x before 11.6.8, and 11.7.x before 11.7.3. It has Incorrect Access Control,

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2022-1940

A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues

CVSS3: 7.7
6%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1783

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for malicious group maintainers to add new members to a project within their group, through the REST API, even after their group owner enabled a setting to prevent members from being added to projects within that group.

CVSS3: 2.7
1%
Низкий
около 4 лет назад
fstec логотип
BDU:2022-03328

Уязвимость функции SCIM (System of Cross-domain Identity Management) программной платформы на базе git для совместной работы над кодом GitLab, связанная с возможностью приглашения произвольных пользователей через свое имя пользователя и адрес электронной почты, позволяющая нарушителю выполнить захват учетных записей пользователей путем изменения адреса их электронной почты

CVSS3: 9.6
15%
Средний
около 4 лет назад
fstec логотип
BDU:2022-03702

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab Enterprise Edition, связанная с недостатками процедуры авторизации, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 6.5
1%
Низкий
около 4 лет назад
fstec логотип
BDU:2022-03705

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab Enterprise Edition, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный код JavaScript

CVSS3: 7.7
6%
Низкий
около 4 лет назад
github логотип
GHSA-f3cp-f6ph-xxhj

In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s password via the change password function. There is a rate limit in place, but the attack may still be conducted by stealing the session id from the physical compromise of the account and splitting the attack over several IP addresses and passing in the compromised session value from these various locations.

0%
Низкий
около 4 лет назад
github логотип
GHSA-h5fq-66m8-wp4v

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 1 of 5).

2%
Низкий
около 4 лет назад
github логотип
GHSA-mv85-vhf6-fp37

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

2%
Низкий
около 4 лет назад
github логотип
GHSA-95hp-m576-m42x

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2244-rvc8-pc38

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.5.10, 11.6.x before 11.6.8, and 11.7.x before 11.7.3. It has Incorrect Access Control,

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться