Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
GHSA-9rx5-594g-qxq8
Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link
GHSA-g5f7-9xpc-633r
An issue has been discovered in GitLab affecting all versions. Improper access control allows unauthorised users to access project details using Graphql.
GHSA-9mfx-3c98-hm2f
A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username.
GHSA-r6rg-m239-gjp4
Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2.
GHSA-67r7-3vf2-fjcp
A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it
GHSA-3f26-542m-36hv
A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim
GHSA-27v4-8jv4-3cp6
Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown
GHSA-68v6-4gjc-qv2v
An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details
GHSA-q5w6-p37j-cwr4
HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE
GHSA-mhq2-mq3h-45cg
An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-9rx5-594g-qxq8 Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link | 1% Низкий | около 4 лет назад | ||
GHSA-g5f7-9xpc-633r An issue has been discovered in GitLab affecting all versions. Improper access control allows unauthorised users to access project details using Graphql. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-9mfx-3c98-hm2f A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username. | 1% Низкий | около 4 лет назад | ||
GHSA-r6rg-m239-gjp4 Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2. | 1% Низкий | около 4 лет назад | ||
GHSA-67r7-3vf2-fjcp A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it | 1% Низкий | около 4 лет назад | ||
GHSA-3f26-542m-36hv A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim | 1% Низкий | около 4 лет назад | ||
GHSA-27v4-8jv4-3cp6 Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown | 1% Низкий | около 4 лет назад | ||
GHSA-68v6-4gjc-qv2v An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-q5w6-p37j-cwr4 HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE | 1% Низкий | около 4 лет назад | ||
GHSA-mhq2-mq3h-45cg An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу