Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
GHSA-gf7j-5934-9pff
In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call.
GHSA-32w9-cgpf-p2wf
Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication
GHSA-jvc7-79q4-7754
In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.
GHSA-8m2q-q4c8-7569
Improper authorization checks in GitLab EE > 13.11 allows subgroup members to see epics from all parent subgroups.
GHSA-pgwc-r5c3-jvg2
In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to trick users into visiting a malicious website by spoofing the content in an error response.
GHSA-cvqc-8rrv-whf2
A Stored XSS in merge request creation page in Gitlab EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names
GHSA-p9m7-w29m-489v
A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.
GHSA-4ccf-v4wp-c858
In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues.
GHSA-g8p8-2v2x-8mhv
Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.
GHSA-7gxg-937v-gfc4
An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-gf7j-5934-9pff In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call. | 1% Низкий | около 4 лет назад | ||
GHSA-32w9-cgpf-p2wf Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication | 0% Низкий | около 4 лет назад | ||
GHSA-jvc7-79q4-7754 In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export. | 1% Низкий | около 4 лет назад | ||
GHSA-8m2q-q4c8-7569 Improper authorization checks in GitLab EE > 13.11 allows subgroup members to see epics from all parent subgroups. | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-pgwc-r5c3-jvg2 In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to trick users into visiting a malicious website by spoofing the content in an error response. | 1% Низкий | около 4 лет назад | ||
GHSA-cvqc-8rrv-whf2 A Stored XSS in merge request creation page in Gitlab EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-p9m7-w29m-489v A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file. | 1% Низкий | около 4 лет назад | ||
GHSA-4ccf-v4wp-c858 In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues. | 1% Низкий | около 4 лет назад | ||
GHSA-g8p8-2v2x-8mhv Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs. | CVSS3: 2.7 | 1% Низкий | около 4 лет назад | |
GHSA-7gxg-937v-gfc4 An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу