Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-m8p6-xp2q-8w7h

около 4 лет назад

A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion.

EPSS: Низкий
github логотип

GHSA-xfxc-c47w-9432

около 4 лет назад

An improper access control flaw in GitLab CE/EE since version 13.9 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xxx4-cx36-38r5

около 4 лет назад

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-6cxq-rcp9-rqr8

около 4 лет назад

Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.

EPSS: Средний
github логотип

GHSA-prvv-j9vx-7x9q

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

EPSS: Низкий
github логотип

GHSA-8j2x-wq4x-63v8

около 4 лет назад

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.

EPSS: Низкий
github логотип

GHSA-2vqg-gr4m-v458

около 4 лет назад

A stored Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.7 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-87qr-9vj6-hjc5

около 4 лет назад

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-vj39-w82r-gvcp

около 4 лет назад

In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-237m-vv9j-66q2

около 4 лет назад

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-m8p6-xp2q-8w7h

A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xfxc-c47w-9432

An improper access control flaw in GitLab CE/EE since version 13.9 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xxx4-cx36-38r5

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-6cxq-rcp9-rqr8

Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.

61%
Средний
около 4 лет назад
github логотип
GHSA-prvv-j9vx-7x9q

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

1%
Низкий
около 4 лет назад
github логотип
GHSA-8j2x-wq4x-63v8

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2vqg-gr4m-v458

A stored Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.7 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-87qr-9vj6-hjc5

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-vj39-w82r-gvcp

In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-237m-vv9j-66q2

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться