Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 918

github логотип

GHSA-6jwf-9gvr-hw8m

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.

EPSS: Низкий
github логотип

GHSA-xcc5-p2w6-cc26

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure.

EPSS: Низкий
github логотип

GHSA-x8c3-w66m-mxxx

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control.

EPSS: Низкий
github логотип

GHSA-9pcc-mx54-f9hq

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection.

EPSS: Низкий
github логотип

GHSA-mh9g-743p-49cw

около 4 лет назад

GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-vgcv-58jw-xrwf

около 4 лет назад

In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

EPSS: Низкий
github логотип

GHSA-9423-j6rv-rhp5

около 4 лет назад

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

EPSS: Низкий
github логотип

GHSA-p39m-p32x-h8jq

около 4 лет назад

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-x7xf-pq3v-j78r

около 4 лет назад

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7rc9-96f5-5rfx

около 4 лет назад

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-6jwf-9gvr-hw8m

An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xcc5-p2w6-cc26

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure.

1%
Низкий
около 4 лет назад
github логотип
GHSA-x8c3-w66m-mxxx

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control.

1%
Низкий
около 4 лет назад
github логотип
GHSA-9pcc-mx54-f9hq

An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection.

3%
Низкий
около 4 лет назад
github логотип
GHSA-mh9g-743p-49cw

GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.

1%
Низкий
около 4 лет назад
github логотип
GHSA-vgcv-58jw-xrwf

In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

1%
Низкий
около 4 лет назад
github логотип
GHSA-9423-j6rv-rhp5

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

1%
Низкий
около 4 лет назад
github логотип
GHSA-p39m-p32x-h8jq

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-x7xf-pq3v-j78r

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-7rc9-96f5-5rfx

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться