Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-gf7j-5934-9pff

около 4 лет назад

In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call.

EPSS: Низкий
github логотип

GHSA-32w9-cgpf-p2wf

около 4 лет назад

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

EPSS: Низкий
github логотип

GHSA-jvc7-79q4-7754

около 4 лет назад

In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.

EPSS: Низкий
github логотип

GHSA-8m2q-q4c8-7569

около 4 лет назад

Improper authorization checks in GitLab EE > 13.11 allows subgroup members to see epics from all parent subgroups.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-pgwc-r5c3-jvg2

около 4 лет назад

In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to trick users into visiting a malicious website by spoofing the content in an error response.

EPSS: Низкий
github логотип

GHSA-cvqc-8rrv-whf2

около 4 лет назад

A Stored XSS in merge request creation page in Gitlab EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-p9m7-w29m-489v

около 4 лет назад

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

EPSS: Низкий
github логотип

GHSA-4ccf-v4wp-c858

около 4 лет назад

In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues.

EPSS: Низкий
github логотип

GHSA-g8p8-2v2x-8mhv

около 4 лет назад

Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-7gxg-937v-gfc4

около 4 лет назад

An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-gf7j-5934-9pff

In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call.

1%
Низкий
около 4 лет назад
github логотип
GHSA-32w9-cgpf-p2wf

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

0%
Низкий
около 4 лет назад
github логотип
GHSA-jvc7-79q4-7754

In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.

1%
Низкий
около 4 лет назад
github логотип
GHSA-8m2q-q4c8-7569

Improper authorization checks in GitLab EE > 13.11 allows subgroup members to see epics from all parent subgroups.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-pgwc-r5c3-jvg2

In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to trick users into visiting a malicious website by spoofing the content in an error response.

1%
Низкий
около 4 лет назад
github логотип
GHSA-cvqc-8rrv-whf2

A Stored XSS in merge request creation page in Gitlab EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-p9m7-w29m-489v

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

1%
Низкий
около 4 лет назад
github логотип
GHSA-4ccf-v4wp-c858

In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues.

1%
Низкий
около 4 лет назад
github логотип
GHSA-g8p8-2v2x-8mhv

Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.

CVSS3: 2.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-7gxg-937v-gfc4

An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться