Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 918
GHSA-6jwf-9gvr-hw8m
An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.
GHSA-xcc5-p2w6-cc26
An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure.
GHSA-x8c3-w66m-mxxx
An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control.
GHSA-9pcc-mx54-f9hq
An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection.
GHSA-mh9g-743p-49cw
GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.
GHSA-vgcv-58jw-xrwf
In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.
GHSA-9423-j6rv-rhp5
Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.
GHSA-p39m-p32x-h8jq
GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.
GHSA-x7xf-pq3v-j78r
GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.
GHSA-7rc9-96f5-5rfx
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-6jwf-9gvr-hw8m An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization. | 1% Низкий | около 4 лет назад | ||
GHSA-xcc5-p2w6-cc26 An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure. | 1% Низкий | около 4 лет назад | ||
GHSA-x8c3-w66m-mxxx An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control. | 1% Низкий | около 4 лет назад | ||
GHSA-9pcc-mx54-f9hq An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection. | 3% Низкий | около 4 лет назад | ||
GHSA-mh9g-743p-49cw GitLab 10.7 and later through 12.7.2 has Incorrect Access Control. | 1% Низкий | около 4 лет назад | ||
GHSA-vgcv-58jw-xrwf In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users. | 1% Низкий | около 4 лет назад | ||
GHSA-9423-j6rv-rhp5 Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo. | 1% Низкий | около 4 лет назад | ||
GHSA-p39m-p32x-h8jq GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline. | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-x7xf-pq3v-j78r GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint. | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-7rc9-96f5-5rfx GitLab EE 8.9 and later through 12.7.2 has Insecure Permission | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу