Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
GHSA-m6pw-2x85-c738
In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.
GHSA-mvf7-889j-9c49
A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.
GHSA-gh46-94pq-p4r3
An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.
GHSA-7w9g-7w46-w7h4
In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.
GHSA-4ff8-x6j5-88r4
In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.
GHSA-q6vr-pm5m-w6c6
The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses
GHSA-w6pv-c757-6rgr
apollo_upload_server has Denial of Service vulnerability
GHSA-xq89-553h-3j4m
In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.
GHSA-wrr4-j76w-2847
A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.
GHSA-h99g-4c6w-94rj
In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-m6pw-2x85-c738 In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call. | 1% Низкий | около 4 лет назад | ||
GHSA-mvf7-889j-9c49 A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation. | 1% Низкий | около 4 лет назад | ||
GHSA-gh46-94pq-p4r3 An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances. | 1% Низкий | около 4 лет назад | ||
GHSA-7w9g-7w46-w7h4 In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch. | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-4ff8-x6j5-88r4 In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description. | 1% Низкий | около 4 лет назад | ||
GHSA-q6vr-pm5m-w6c6 The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses | 1% Низкий | около 4 лет назад | ||
GHSA-w6pv-c757-6rgr apollo_upload_server has Denial of Service vulnerability | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-xq89-553h-3j4m In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure. | CVSS3: 4.9 | 1% Низкий | около 4 лет назад | |
GHSA-wrr4-j76w-2847 A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API. | 1% Низкий | около 4 лет назад | ||
GHSA-h99g-4c6w-94rj In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу