Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-9rx5-594g-qxq8

около 4 лет назад

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

EPSS: Низкий
github логотип

GHSA-g5f7-9xpc-633r

около 4 лет назад

An issue has been discovered in GitLab affecting all versions. Improper access control allows unauthorised users to access project details using Graphql.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9mfx-3c98-hm2f

около 4 лет назад

A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username.

EPSS: Низкий
github логотип

GHSA-r6rg-m239-gjp4

около 4 лет назад

Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2.

EPSS: Низкий
github логотип

GHSA-67r7-3vf2-fjcp

около 4 лет назад

A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it

EPSS: Низкий
github логотип

GHSA-3f26-542m-36hv

около 4 лет назад

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

EPSS: Низкий
github логотип

GHSA-27v4-8jv4-3cp6

около 4 лет назад

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

EPSS: Низкий
github логотип

GHSA-68v6-4gjc-qv2v

около 4 лет назад

An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-q5w6-p37j-cwr4

около 4 лет назад

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

EPSS: Низкий
github логотип

GHSA-mhq2-mq3h-45cg

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-9rx5-594g-qxq8

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

1%
Низкий
около 4 лет назад
github логотип
GHSA-g5f7-9xpc-633r

An issue has been discovered in GitLab affecting all versions. Improper access control allows unauthorised users to access project details using Graphql.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-9mfx-3c98-hm2f

A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username.

1%
Низкий
около 4 лет назад
github логотип
GHSA-r6rg-m239-gjp4

Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2.

1%
Низкий
около 4 лет назад
github логотип
GHSA-67r7-3vf2-fjcp

A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it

1%
Низкий
около 4 лет назад
github логотип
GHSA-3f26-542m-36hv

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

1%
Низкий
около 4 лет назад
github логотип
GHSA-27v4-8jv4-3cp6

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

1%
Низкий
около 4 лет назад
github логотип
GHSA-68v6-4gjc-qv2v

An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-q5w6-p37j-cwr4

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

1%
Низкий
около 4 лет назад
github логотип
GHSA-mhq2-mq3h-45cg

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться