Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-w673-w4h7-244x

около 4 лет назад

Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9

EPSS: Низкий
github логотип

GHSA-jhg6-6fpm-5p2r

около 4 лет назад

A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources.

EPSS: Низкий
github логотип

GHSA-4gm2-v7j4-74p8

около 4 лет назад

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-6jpw-pq5v-3x7w

около 4 лет назад

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

EPSS: Средний
github логотип

GHSA-6qcx-wmcg-gqpq

около 4 лет назад

All versions of GitLab CE/EE starting with 12.8 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-r8qj-g779-h5pv

около 4 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q99w-5q7g-6x5x

около 4 лет назад

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-m8j6-rg22-ww2f

около 4 лет назад

An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-2p89-vr82-6vw5

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired

EPSS: Низкий
github логотип

GHSA-85ch-gvj9-wmwc

около 4 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-w673-w4h7-244x

Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9

1%
Низкий
около 4 лет назад
github логотип
GHSA-jhg6-6fpm-5p2r

A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources.

1%
Низкий
около 4 лет назад
github логотип
GHSA-4gm2-v7j4-74p8

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

CVSS3: 9.8
53%
Средний
около 4 лет назад
github логотип
GHSA-6jpw-pq5v-3x7w

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

28%
Средний
около 4 лет назад
github логотип
GHSA-6qcx-wmcg-gqpq

All versions of GitLab CE/EE starting with 12.8 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
0%
Низкий
около 4 лет назад
github логотип
GHSA-r8qj-g779-h5pv

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-q99w-5q7g-6x5x

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-m8j6-rg22-ww2f

An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects

CVSS3: 2.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-2p89-vr82-6vw5

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired

1%
Низкий
около 4 лет назад
github логотип
GHSA-85ch-gvj9-wmwc

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться