Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-jr4h-pv5f-qr33

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

EPSS: Низкий
github логотип

GHSA-p246-m8pm-4pjp

около 4 лет назад

GitLab CE/EE since version 9.5 allows a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-79w6-c88v-gfgr

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.

EPSS: Низкий
github логотип

GHSA-6g79-3r2c-5vxg

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,

EPSS: Низкий
github логотип

GHSA-c8rf-2f6q-cprc

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.

EPSS: Низкий
github логотип

GHSA-m2g4-fcc3-wp4v

около 4 лет назад

An issue has been discovered in GitLab affecting versions starting with 13.5 up to 13.9.7. Improper permission check could allow the change of timestamp for issue creation or update.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-wvv5-79h5-39g9

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.

EPSS: Низкий
github логотип

GHSA-vgp2-3hxm-6x85

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

CVSS3: 10
EPSS: Критический
github логотип

GHSA-gc6j-24mw-538j

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting with 12.9. GitLab was vulnerable to a stored XSS if scoped labels were used.

EPSS: Низкий
github логотип

GHSA-5hrw-2pjr-f25r

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all previous versions. If the victim is an admin, it was possible to issue a CSRF in System hooks through the API.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-jr4h-pv5f-qr33

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

1%
Низкий
около 4 лет назад
github логотип
GHSA-p246-m8pm-4pjp

GitLab CE/EE since version 9.5 allows a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.

CVSS3: 4.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-79w6-c88v-gfgr

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.

1%
Низкий
около 4 лет назад
github логотип
GHSA-6g79-3r2c-5vxg

An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,

1%
Низкий
около 4 лет назад
github логотип
GHSA-c8rf-2f6q-cprc

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.

1%
Низкий
около 4 лет назад
github логотип
GHSA-m2g4-fcc3-wp4v

An issue has been discovered in GitLab affecting versions starting with 13.5 up to 13.9.7. Improper permission check could allow the change of timestamp for issue creation or update.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-wvv5-79h5-39g9

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.

1%
Низкий
около 4 лет назад
github логотип
GHSA-vgp2-3hxm-6x85

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

CVSS3: 10
100%
Критический
около 4 лет назад
github логотип
GHSA-gc6j-24mw-538j

An issue has been discovered in GitLab affecting all versions starting with 12.9. GitLab was vulnerable to a stored XSS if scoped labels were used.

1%
Низкий
около 4 лет назад
github логотип
GHSA-5hrw-2pjr-f25r

An issue has been discovered in GitLab CE/EE affecting all previous versions. If the victim is an admin, it was possible to issue a CSRF in System hooks through the API.

0%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться