Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 871

github логотип

GHSA-vx8w-6r69-h5fv

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2pc6-768q-99h7

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.

EPSS: Низкий
github логотип

GHSA-fvvr-8pf3-2fhf

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Under certain circumstances, CI pipelines could potentially be used in a denial of service attack.

EPSS: Низкий
github логотип

GHSA-8ggg-8hjr-fmv7

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment on merge requests despite the repository being set to allow only project members to do so.

EPSS: Низкий
github логотип

GHSA-89gh-7gfw-7rqp

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1. Insufficient permission checks were being applied when displaying CI results, potentially exposing some CI metrics data to unauthorized users.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-c89r-pq4x-7rmr

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1. The Jira integration contains a SSRF vulnerability as a result of a bypass of the current protection mechanisms against this type of attack, which would allow sending requests to any resources accessible in the local network by the GitLab server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-pg9r-mg67-jxwg

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in markdown could be pointed to an arbitrary server, which would reveal the IP address of clients requesting the file from that server.

EPSS: Низкий
github логотип

GHSA-79gc-8hc2-gp5v

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, commit titles and team member comments could become viewable to users who did not have permission to access these.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-9wrx-mw8f-hx7p

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5jcx-pvq7-vfwp

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-vx8w-6r69-h5fv

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-2pc6-768q-99h7

An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.

2%
Низкий
около 4 лет назад
github логотип
GHSA-fvvr-8pf3-2fhf

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Under certain circumstances, CI pipelines could potentially be used in a denial of service attack.

2%
Низкий
около 4 лет назад
github логотип
GHSA-8ggg-8hjr-fmv7

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment on merge requests despite the repository being set to allow only project members to do so.

1%
Низкий
около 4 лет назад
github логотип
GHSA-89gh-7gfw-7rqp

An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1. Insufficient permission checks were being applied when displaying CI results, potentially exposing some CI metrics data to unauthorized users.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-c89r-pq4x-7rmr

An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1. The Jira integration contains a SSRF vulnerability as a result of a bypass of the current protection mechanisms against this type of attack, which would allow sending requests to any resources accessible in the local network by the GitLab server.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-pg9r-mg67-jxwg

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in markdown could be pointed to an arbitrary server, which would reveal the IP address of clients requesting the file from that server.

2%
Низкий
около 4 лет назад
github логотип
GHSA-79gc-8hc2-gp5v

An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, commit titles and team member comments could become viewable to users who did not have permission to access these.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-9wrx-mw8f-hx7p

An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-5jcx-pvq7-vfwp

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться