Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-h963-mpc3-j9g4

около 4 лет назад

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

EPSS: Низкий
github логотип

GHSA-w2fr-4vgx-vq96

около 4 лет назад

Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3r2f-rpgw-83gm

около 4 лет назад

Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

EPSS: Средний
github логотип

GHSA-q7jc-qjq2-4cmx

около 4 лет назад

Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group.

EPSS: Низкий
github логотип

GHSA-7rmh-fw46-g93m

около 4 лет назад

Improper validation of commit author in GitLab CE/EE affecting all versions allowed an attacker to make several pages in a project impossible to view

EPSS: Низкий
github логотип

GHSA-p3jh-342h-w8hj

около 4 лет назад

Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2

EPSS: Низкий
github логотип

GHSA-jrrv-jm33-8jrv

около 4 лет назад

Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6xw3-8926-pq6q

около 4 лет назад

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

EPSS: Низкий
github логотип

GHSA-fhrq-2vr4-f65r

около 4 лет назад

Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics

EPSS: Низкий
github логотип

GHSA-c877-4h7h-xvp6

около 4 лет назад

A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to Maintainers

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-h963-mpc3-j9g4

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

1%
Низкий
около 4 лет назад
github логотип
GHSA-w2fr-4vgx-vq96

Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-3r2f-rpgw-83gm

Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

64%
Средний
около 4 лет назад
github логотип
GHSA-q7jc-qjq2-4cmx

Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group.

1%
Низкий
около 4 лет назад
github логотип
GHSA-7rmh-fw46-g93m

Improper validation of commit author in GitLab CE/EE affecting all versions allowed an attacker to make several pages in a project impossible to view

1%
Низкий
около 4 лет назад
github логотип
GHSA-p3jh-342h-w8hj

Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2

1%
Низкий
около 4 лет назад
github логотип
GHSA-jrrv-jm33-8jrv

Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-6xw3-8926-pq6q

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

1%
Низкий
около 4 лет назад
github логотип
GHSA-fhrq-2vr4-f65r

Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics

1%
Низкий
около 4 лет назад
github логотип
GHSA-c877-4h7h-xvp6

A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to Maintainers

CVSS3: 6.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться