Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
GHSA-g3q8-7g5m-j8cw
GitLab EE 11.0 and later through 12.7.2 allows XSS.
GHSA-96jx-9q3w-f653
GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.
GHSA-6cc7-2783-374p
GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.
GHSA-wh39-vq4j-xpj4
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
GHSA-5mpx-m64g-xxgq
GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).
GHSA-793m-qh53-f8pj
GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.
GHSA-cvvf-6v6p-vxjx
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
GHSA-rm66-gh27-q674
An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.
GHSA-qj8w-vx7m-776m
An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account.
GHSA-p58m-cp94-fm4f
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-g3q8-7g5m-j8cw GitLab EE 11.0 and later through 12.7.2 allows XSS. | 1% Низкий | около 4 лет назад | ||
GHSA-96jx-9q3w-f653 GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions. | 1% Низкий | около 4 лет назад | ||
GHSA-6cc7-2783-374p GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control. | 1% Низкий | около 4 лет назад | ||
GHSA-wh39-vq4j-xpj4 GitLab EE 8.0 through 12.7.2 has Incorrect Access Control. | 1% Низкий | около 4 лет назад | ||
GHSA-5mpx-m64g-xxgq GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2). | 1% Низкий | около 4 лет назад | ||
GHSA-793m-qh53-f8pj GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure. | 1% Низкий | около 4 лет назад | ||
GHSA-cvvf-6v6p-vxjx GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal. | 2% Низкий | около 4 лет назад | ||
GHSA-rm66-gh27-q674 An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling. | 1% Низкий | около 4 лет назад | ||
GHSA-qj8w-vx7m-776m An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account. | CVSS3: 8.8 | 2% Низкий | около 4 лет назад | |
GHSA-p58m-cp94-fm4f An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу