Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-m6pw-2x85-c738

около 4 лет назад

In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.

EPSS: Низкий
github логотип

GHSA-mvf7-889j-9c49

около 4 лет назад

A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

EPSS: Низкий
github логотип

GHSA-gh46-94pq-p4r3

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.

EPSS: Низкий
github логотип

GHSA-7w9g-7w46-w7h4

около 4 лет назад

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4ff8-x6j5-88r4

около 4 лет назад

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

EPSS: Низкий
github логотип

GHSA-q6vr-pm5m-w6c6

около 4 лет назад

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

EPSS: Низкий
github логотип

GHSA-w6pv-c757-6rgr

около 4 лет назад

apollo_upload_server has Denial of Service vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq89-553h-3j4m

около 4 лет назад

In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-wrr4-j76w-2847

около 4 лет назад

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

EPSS: Низкий
github логотип

GHSA-h99g-4c6w-94rj

около 4 лет назад

In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-m6pw-2x85-c738

In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.

1%
Низкий
около 4 лет назад
github логотип
GHSA-mvf7-889j-9c49

A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

1%
Низкий
около 4 лет назад
github логотип
GHSA-gh46-94pq-p4r3

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.

1%
Низкий
около 4 лет назад
github логотип
GHSA-7w9g-7w46-w7h4

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-4ff8-x6j5-88r4

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

1%
Низкий
около 4 лет назад
github логотип
GHSA-q6vr-pm5m-w6c6

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

1%
Низкий
около 4 лет назад
github логотип
GHSA-w6pv-c757-6rgr

apollo_upload_server has Denial of Service vulnerability

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xq89-553h-3j4m

In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

CVSS3: 4.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-wrr4-j76w-2847

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

1%
Низкий
около 4 лет назад
github логотип
GHSA-h99g-4c6w-94rj

In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться