Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-27p2-q4g5-wxm8

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS in the epics page, which could be exploited with user interactions.

EPSS: Низкий
github логотип

GHSA-57pj-jxfw-3mpj

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting with 13.7. GitLab was vulnerable to a stored XSS in merge request.

EPSS: Низкий
github логотип

GHSA-4343-v7g7-q3hr

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorised user via branch logs.

EPSS: Низкий
github логотип

GHSA-jx85-pcwq-c9wc

около 4 лет назад

An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 12.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fj94-q44p-pf8f

около 4 лет назад

An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method

EPSS: Низкий
github логотип

GHSA-2j76-jpwv-99mp

около 4 лет назад

Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link

EPSS: Низкий
github логотип

GHSA-q84m-97hf-554f

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository

EPSS: Низкий
github логотип

GHSA-7w6h-978p-xvrg

около 4 лет назад

A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.

EPSS: Низкий
github логотип

GHSA-hwx9-j325-fw69

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

EPSS: Низкий
github логотип

GHSA-5m57-mhq7-6vhf

около 4 лет назад

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-27p2-q4g5-wxm8

An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS in the epics page, which could be exploited with user interactions.

1%
Низкий
около 4 лет назад
github логотип
GHSA-57pj-jxfw-3mpj

An issue has been discovered in GitLab affecting all versions starting with 13.7. GitLab was vulnerable to a stored XSS in merge request.

1%
Низкий
около 4 лет назад
github логотип
GHSA-4343-v7g7-q3hr

An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorised user via branch logs.

1%
Низкий
около 4 лет назад
github логотип
GHSA-jx85-pcwq-c9wc

An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 12.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-fj94-q44p-pf8f

An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method

1%
Низкий
около 4 лет назад
github логотип
GHSA-2j76-jpwv-99mp

Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link

1%
Низкий
около 4 лет назад
github логотип
GHSA-q84m-97hf-554f

An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository

2%
Низкий
около 4 лет назад
github логотип
GHSA-7w6h-978p-xvrg

A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.

1%
Низкий
около 4 лет назад
github логотип
GHSA-hwx9-j325-fw69

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

2%
Низкий
около 4 лет назад
github логотип
GHSA-5m57-mhq7-6vhf

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться