Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
GHSA-p7jp-3g8m-8m7m
A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1
GHSA-jmw9-579m-cw2x
OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow
GHSA-3xg5-7r36-7647
A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1
GHSA-pw3w-gf65-52v7
Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link
GHSA-gfrc-x46r-5mpj
A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1
GHSA-5p95-g2w7-2rfh
Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code
GHSA-4h9q-f95v-pf5f
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.
GHSA-23r2-7xm3-g75g
An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5
GHSA-g6g8-99m5-jj82
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
GHSA-279g-54q8-w7ww
A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-p7jp-3g8m-8m7m A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1 | 1% Низкий | около 4 лет назад | ||
GHSA-jmw9-579m-cw2x OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow | 1% Низкий | около 4 лет назад | ||
GHSA-3xg5-7r36-7647 A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1 | 1% Низкий | около 4 лет назад | ||
GHSA-pw3w-gf65-52v7 Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link | 1% Низкий | около 4 лет назад | ||
GHSA-gfrc-x46r-5mpj A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1 | 1% Низкий | около 4 лет назад | ||
GHSA-5p95-g2w7-2rfh Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code | 1% Низкий | около 4 лет назад | ||
GHSA-4h9q-f95v-pf5f An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions. | 1% Низкий | около 4 лет назад | ||
GHSA-23r2-7xm3-g75g An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5 | 2% Низкий | около 4 лет назад | ||
GHSA-g6g8-99m5-jj82 libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring. | CVSS3: 5.3 | 4% Низкий | около 4 лет назад | |
GHSA-279g-54q8-w7ww A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу