Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 871
GHSA-xhg3-wf98-646c
GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.
GHSA-4hq6-hm84-9r6r
GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.
GHSA-4mm8-64px-38hf
GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.
GHSA-5qpg-r237-3pm4
GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.
GHSA-785p-hcfx-v324
GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.
GHSA-67pm-cqhh-vcqx
GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.
GHSA-6q57-rfmx-mxr3
GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,
GHSA-fjgv-pw7x-g797
GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.
GHSA-q5jf-8f55-j92v
GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.
GHSA-mch5-32hg-65cq
GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-xhg3-wf98-646c GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature. | 1% Низкий | около 4 лет назад | ||
GHSA-4hq6-hm84-9r6r GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-4mm8-64px-38hf GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration. | 1% Низкий | около 4 лет назад | ||
GHSA-5qpg-r237-3pm4 GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles. | 1% Низкий | около 4 лет назад | ||
GHSA-785p-hcfx-v324 GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied. | 1% Низкий | около 4 лет назад | ||
GHSA-67pm-cqhh-vcqx GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed. | 1% Низкий | около 4 лет назад | ||
GHSA-6q57-rfmx-mxr3 GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother, | 1% Низкий | около 4 лет назад | ||
GHSA-fjgv-pw7x-g797 GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types. | 1% Низкий | около 4 лет назад | ||
GHSA-q5jf-8f55-j92v GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level. | 1% Низкий | около 4 лет назад | ||
GHSA-mch5-32hg-65cq GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу