Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-5f6w-rj6x-7j7v

около 4 лет назад

Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings

EPSS: Низкий
github логотип

GHSA-q297-5xx3-gw53

около 4 лет назад

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed

EPSS: Низкий
github логотип

GHSA-w37f-8cwf-64g5

около 4 лет назад

Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-5mm2-786g-8qwh

около 4 лет назад

A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group

EPSS: Низкий
github логотип

GHSA-fc33-2q9r-qr2m

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

EPSS: Высокий
github логотип

GHSA-q6jf-84qm-cj59

около 4 лет назад

A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of service attacks.

EPSS: Низкий
github логотип

GHSA-g4px-p74v-q4c7

около 4 лет назад

Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9.

EPSS: Низкий
github логотип

GHSA-79vw-576r-jwjv

около 4 лет назад

Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled

EPSS: Низкий
github логотип

GHSA-98vw-hfg6-8fjf

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name.

EPSS: Низкий
github логотип

GHSA-gj8c-fhmc-cqpg

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 13.11, 13.12 and 14.0. A specially crafted design image allowed attackers to read arbitrary files on the server.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-5f6w-rj6x-7j7v

Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings

1%
Низкий
около 4 лет назад
github логотип
GHSA-q297-5xx3-gw53

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed

1%
Низкий
около 4 лет назад
github логотип
GHSA-w37f-8cwf-64g5

Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-5mm2-786g-8qwh

A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group

1%
Низкий
около 4 лет назад
github логотип
GHSA-fc33-2q9r-qr2m

An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

72%
Высокий
около 4 лет назад
github логотип
GHSA-q6jf-84qm-cj59

A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of service attacks.

1%
Низкий
около 4 лет назад
github логотип
GHSA-g4px-p74v-q4c7

Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9.

1%
Низкий
около 4 лет назад
github логотип
GHSA-79vw-576r-jwjv

Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled

1%
Низкий
около 4 лет назад
github логотип
GHSA-98vw-hfg6-8fjf

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name.

1%
Низкий
около 4 лет назад
github логотип
GHSA-gj8c-fhmc-cqpg

An issue has been discovered in GitLab CE/EE affecting all versions starting with 13.11, 13.12 and 14.0. A specially crafted design image allowed attackers to read arbitrary files on the server.

CVSS3: 6.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться