Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
GHSA-q49w-v89m-366g
In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.
GHSA-2fmv-g8v2-32hj
In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page.
GHSA-r68r-r23h-fpvc
In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page
GHSA-35pq-fvh7-h49r
In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.
GHSA-22mg-qg4r-wh4q
In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.
GHSA-6c6c-hp4f-xg67
In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.
GHSA-prwp-cpfg-vppq
GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.
GHSA-p4rh-pv9g-cw9x
Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token
GHSA-hg4v-vm5j-rq45
User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1
GHSA-qcrv-74q6-jcj4
User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-q49w-v89m-366g In GitLab before 13.2.3, project sharing could temporarily allow too permissive access. | 1% Низкий | около 4 лет назад | ||
GHSA-2fmv-g8v2-32hj In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page. | 1% Низкий | около 4 лет назад | ||
GHSA-r68r-r23h-fpvc In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page | 4% Низкий | около 4 лет назад | ||
GHSA-35pq-fvh7-h49r In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow. | 1% Низкий | около 4 лет назад | ||
GHSA-22mg-qg4r-wh4q In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application. | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-6c6c-hp4f-xg67 In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash. | 1% Низкий | около 4 лет назад | ||
GHSA-prwp-cpfg-vppq GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint. | 1% Низкий | около 4 лет назад | ||
GHSA-p4rh-pv9g-cw9x Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token | 1% Низкий | около 4 лет назад | ||
GHSA-hg4v-vm5j-rq45 User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1 | 1% Низкий | около 4 лет назад | ||
GHSA-qcrv-74q6-jcj4 User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу