Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-q49w-v89m-366g

около 4 лет назад

In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.

EPSS: Низкий
github логотип

GHSA-2fmv-g8v2-32hj

около 4 лет назад

In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page.

EPSS: Низкий
github логотип

GHSA-r68r-r23h-fpvc

около 4 лет назад

In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page

EPSS: Низкий
github логотип

GHSA-35pq-fvh7-h49r

около 4 лет назад

In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.

EPSS: Низкий
github логотип

GHSA-22mg-qg4r-wh4q

около 4 лет назад

In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-6c6c-hp4f-xg67

около 4 лет назад

In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.

EPSS: Низкий
github логотип

GHSA-prwp-cpfg-vppq

около 4 лет назад

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.

EPSS: Низкий
github логотип

GHSA-p4rh-pv9g-cw9x

около 4 лет назад

Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token

EPSS: Низкий
github логотип

GHSA-hg4v-vm5j-rq45

около 4 лет назад

User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1

EPSS: Низкий
github логотип

GHSA-qcrv-74q6-jcj4

около 4 лет назад

User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-q49w-v89m-366g

In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2fmv-g8v2-32hj

In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page.

1%
Низкий
около 4 лет назад
github логотип
GHSA-r68r-r23h-fpvc

In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page

4%
Низкий
около 4 лет назад
github логотип
GHSA-35pq-fvh7-h49r

In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.

1%
Низкий
около 4 лет назад
github логотип
GHSA-22mg-qg4r-wh4q

In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-6c6c-hp4f-xg67

In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.

1%
Низкий
около 4 лет назад
github логотип
GHSA-prwp-cpfg-vppq

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.

1%
Низкий
около 4 лет назад
github логотип
GHSA-p4rh-pv9g-cw9x

Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token

1%
Низкий
около 4 лет назад
github логотип
GHSA-hg4v-vm5j-rq45

User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1

1%
Низкий
около 4 лет назад
github логотип
GHSA-qcrv-74q6-jcj4

User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться