Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-p7jp-3g8m-8m7m

около 4 лет назад

A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1

EPSS: Низкий
github логотип

GHSA-jmw9-579m-cw2x

около 4 лет назад

OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow

EPSS: Низкий
github логотип

GHSA-3xg5-7r36-7647

около 4 лет назад

A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1

EPSS: Низкий
github логотип

GHSA-pw3w-gf65-52v7

около 4 лет назад

Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link

EPSS: Низкий
github логотип

GHSA-gfrc-x46r-5mpj

около 4 лет назад

A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1

EPSS: Низкий
github логотип

GHSA-5p95-g2w7-2rfh

около 4 лет назад

Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code

EPSS: Низкий
github логотип

GHSA-4h9q-f95v-pf5f

около 4 лет назад

An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.

EPSS: Низкий
github логотип

GHSA-23r2-7xm3-g75g

около 4 лет назад

An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5

EPSS: Низкий
github логотип

GHSA-g6g8-99m5-jj82

около 4 лет назад

libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-279g-54q8-w7ww

около 4 лет назад

A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-p7jp-3g8m-8m7m

A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1

1%
Низкий
около 4 лет назад
github логотип
GHSA-jmw9-579m-cw2x

OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow

1%
Низкий
около 4 лет назад
github логотип
GHSA-3xg5-7r36-7647

A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1

1%
Низкий
около 4 лет назад
github логотип
GHSA-pw3w-gf65-52v7

Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link

1%
Низкий
около 4 лет назад
github логотип
GHSA-gfrc-x46r-5mpj

A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1

1%
Низкий
около 4 лет назад
github логотип
GHSA-5p95-g2w7-2rfh

Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code

1%
Низкий
около 4 лет назад
github логотип
GHSA-4h9q-f95v-pf5f

An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.

1%
Низкий
около 4 лет назад
github логотип
GHSA-23r2-7xm3-g75g

An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5

2%
Низкий
около 4 лет назад
github логотип
GHSA-g6g8-99m5-jj82

libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

CVSS3: 5.3
4%
Низкий
около 4 лет назад
github логотип
GHSA-279g-54q8-w7ww

A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1

2%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться