Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-vgcv-58jw-xrwf

около 4 лет назад

In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

EPSS: Низкий
github логотип

GHSA-9423-j6rv-rhp5

около 4 лет назад

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

EPSS: Низкий
github логотип

GHSA-x7xf-pq3v-j78r

около 4 лет назад

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-p39m-p32x-h8jq

около 4 лет назад

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-gxcq-53fv-9j43

около 4 лет назад

GitLab EE 10.1 through 12.7.2 allows Information Disclosure.

EPSS: Низкий
github логотип

GHSA-r4qm-gf89-653c

около 4 лет назад

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

EPSS: Низкий
github логотип

GHSA-7rc9-96f5-5rfx

около 4 лет назад

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

EPSS: Низкий
github логотип

GHSA-frwx-hm63-346w

около 4 лет назад

GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).

EPSS: Низкий
github логотип

GHSA-6xcc-cmr2-r357

около 4 лет назад

GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.

EPSS: Низкий
github логотип

GHSA-9r3x-jfv9-5w6c

около 4 лет назад

GitLab through 12.7.2 allows XSS.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-vgcv-58jw-xrwf

In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

1%
Низкий
около 4 лет назад
github логотип
GHSA-9423-j6rv-rhp5

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

1%
Низкий
около 4 лет назад
github логотип
GHSA-x7xf-pq3v-j78r

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-p39m-p32x-h8jq

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-gxcq-53fv-9j43

GitLab EE 10.1 through 12.7.2 allows Information Disclosure.

1%
Низкий
около 4 лет назад
github логотип
GHSA-r4qm-gf89-653c

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

1%
Низкий
около 4 лет назад
github логотип
GHSA-7rc9-96f5-5rfx

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

1%
Низкий
около 4 лет назад
github логотип
GHSA-frwx-hm63-346w

GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).

1%
Низкий
около 4 лет назад
github логотип
GHSA-6xcc-cmr2-r357

GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.

1%
Низкий
около 4 лет назад
github логотип
GHSA-9r3x-jfv9-5w6c

GitLab through 12.7.2 allows XSS.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться