Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-67pm-cqhh-vcqx

около 4 лет назад

GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.

EPSS: Низкий
github логотип

GHSA-3jmg-94rq-h4hm

около 4 лет назад

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.

EPSS: Низкий
github логотип

GHSA-qj9x-qgqc-v252

около 4 лет назад

GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace

EPSS: Низкий
github логотип

GHSA-jg7j-6r85-5w9p

около 4 лет назад

GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.

EPSS: Низкий
github логотип

GHSA-mch5-32hg-65cq

около 4 лет назад

GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.

EPSS: Низкий
github логотип

GHSA-qgvm-92m2-j87g

около 4 лет назад

GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jcr-4r89-72r6

около 4 лет назад

GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.

EPSS: Низкий
github логотип

GHSA-ch28-63rq-r3fw

около 4 лет назад

GitLab 12.2 through 12.8.1 allows Denial of Service. A denial of service vulnerability impacting the designs for public issues was discovered.

EPSS: Низкий
github логотип

GHSA-8wjh-279q-q77p

около 4 лет назад

GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.

EPSS: Низкий
github логотип

GHSA-686p-7q3m-4r7x

около 4 лет назад

GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-67pm-cqhh-vcqx

GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3jmg-94rq-h4hm

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.

1%
Низкий
около 4 лет назад
github логотип
GHSA-qj9x-qgqc-v252

GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace

1%
Низкий
около 4 лет назад
github логотип
GHSA-jg7j-6r85-5w9p

GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.

1%
Низкий
около 4 лет назад
github логотип
GHSA-mch5-32hg-65cq

GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.

1%
Низкий
около 4 лет назад
github логотип
GHSA-qgvm-92m2-j87g

GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2jcr-4r89-72r6

GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.

1%
Низкий
около 4 лет назад
github логотип
GHSA-ch28-63rq-r3fw

GitLab 12.2 through 12.8.1 allows Denial of Service. A denial of service vulnerability impacting the designs for public issues was discovered.

1%
Низкий
около 4 лет назад
github логотип
GHSA-8wjh-279q-q77p

GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.

1%
Низкий
около 4 лет назад
github логотип
GHSA-686p-7q3m-4r7x

GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться