Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-vg95-5p98-2464

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-58g4-wwj5-gcwg

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server.

EPSS: Средний
github логотип

GHSA-289v-j7vm-cm7q

около 4 лет назад

A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature.

EPSS: Низкий
github логотип

GHSA-wf25-2f67-3rmc

около 4 лет назад

Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted commit to a wiki

EPSS: Низкий
github логотип

GHSA-g5rc-vv3j-cq5q

около 4 лет назад

An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners

EPSS: Низкий
github логотип

GHSA-2j7r-vr72-m9vf

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specific name for private project.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-x4h7-gg27-pw2v

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-637p-mqw3-h377

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration.

EPSS: Низкий
github логотип

GHSA-42jq-pvpx-7m8x

около 4 лет назад

An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-39rg-m8qv-7ff5

около 4 лет назад

Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-vg95-5p98-2464

An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-58g4-wwj5-gcwg

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server.

13%
Средний
около 4 лет назад
github логотип
GHSA-289v-j7vm-cm7q

A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature.

1%
Низкий
около 4 лет назад
github логотип
GHSA-wf25-2f67-3rmc

Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted commit to a wiki

1%
Низкий
около 4 лет назад
github логотип
GHSA-g5rc-vv3j-cq5q

An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners

1%
Низкий
около 4 лет назад
github логотип
GHSA-2j7r-vr72-m9vf

An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specific name for private project.

CVSS3: 3.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-x4h7-gg27-pw2v

An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-637p-mqw3-h377

An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration.

1%
Низкий
около 4 лет назад
github логотип
GHSA-42jq-pvpx-7m8x

An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-39rg-m8qv-7ff5

Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться