Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
GHSA-m8p6-xp2q-8w7h
A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion.
GHSA-xfxc-c47w-9432
An improper access control flaw in GitLab CE/EE since version 13.9 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers
GHSA-xxx4-cx36-38r5
Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances
GHSA-6cxq-rcp9-rqr8
Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.
GHSA-prvv-j9vx-7x9q
An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.
GHSA-8j2x-wq4x-63v8
A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.
GHSA-2vqg-gr4m-v458
A stored Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.7 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses
GHSA-87qr-9vj6-hjc5
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
GHSA-vj39-w82r-gvcp
In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
GHSA-237m-vv9j-66q2
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-m8p6-xp2q-8w7h A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion. | 1% Низкий | около 4 лет назад | ||
GHSA-xfxc-c47w-9432 An improper access control flaw in GitLab CE/EE since version 13.9 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-xxx4-cx36-38r5 Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-6cxq-rcp9-rqr8 Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf. | 61% Средний | около 4 лет назад | ||
GHSA-prvv-j9vx-7x9q An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects. | 1% Низкий | около 4 лет назад | ||
GHSA-8j2x-wq4x-63v8 A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf. | 1% Низкий | около 4 лет назад | ||
GHSA-2vqg-gr4m-v458 A stored Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.7 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses | CVSS3: 4.8 | 1% Низкий | около 4 лет назад | |
GHSA-87qr-9vj6-hjc5 A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens. | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-vj39-w82r-gvcp In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-237m-vv9j-66q2 In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу