Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-j34f-v6r4-25vh

около 4 лет назад

Missing access control in GitLab version 13.10 and above with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-352f-q892-q47q

около 4 лет назад

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

EPSS: Низкий
github логотип

GHSA-mq9g-jw9v-3pcf

около 4 лет назад

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-v95j-qhvj-8v9x

около 4 лет назад

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

EPSS: Низкий
github логотип

GHSA-96jg-v9jf-qq4p

около 4 лет назад

In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-6463-hw74-9748

около 4 лет назад

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

EPSS: Низкий
github логотип

GHSA-h93h-vj2c-pxf9

около 4 лет назад

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

EPSS: Низкий
github логотип

GHSA-6482-jw4x-5vc6

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

EPSS: Низкий
github логотип

GHSA-mw77-7v4x-3mh4

около 4 лет назад

In all versions of GitLab EE since version 13.10, a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-cxfj-qcv7-fx7w

около 4 лет назад

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-j34f-v6r4-25vh

Missing access control in GitLab version 13.10 and above with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-352f-q892-q47q

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

1%
Низкий
около 4 лет назад
github логотип
GHSA-mq9g-jw9v-3pcf

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-v95j-qhvj-8v9x

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

1%
Низкий
около 4 лет назад
github логотип
GHSA-96jg-v9jf-qq4p

In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-6463-hw74-9748

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

1%
Низкий
около 4 лет назад
github логотип
GHSA-h93h-vj2c-pxf9

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

1%
Низкий
около 4 лет назад
github логотип
GHSA-6482-jw4x-5vc6

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

1%
Низкий
около 4 лет назад
github логотип
GHSA-mw77-7v4x-3mh4

In all versions of GitLab EE since version 13.10, a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-cxfj-qcv7-fx7w

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться