Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-wqrm-4jcg-5rjc

около 4 лет назад

An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.

EPSS: Низкий
github логотип

GHSA-x79q-qfgr-wrvw

около 4 лет назад

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

EPSS: Низкий
github логотип

GHSA-p46f-r59p-v4jf

около 4 лет назад

An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gpm-g93x-8fr4

около 4 лет назад

An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-55ff-j47x-6xcq

около 4 лет назад

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

EPSS: Низкий
github логотип

GHSA-rvxr-qvvc-m3g5

около 4 лет назад

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.

EPSS: Низкий
github логотип

GHSA-ff73-cwc3-6v5j

около 4 лет назад

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

EPSS: Низкий
github логотип

GHSA-cfp2-8mw9-wg68

около 4 лет назад

An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w772-f4fj-g5xq

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4. It has Insecure Permissions.

EPSS: Низкий
github логотип

GHSA-645m-h3pw-m72w

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-wqrm-4jcg-5rjc

An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.

1%
Низкий
около 4 лет назад
github логотип
GHSA-x79q-qfgr-wrvw

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

2%
Низкий
около 4 лет назад
github логотип
GHSA-p46f-r59p-v4jf

An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2gpm-g93x-8fr4

An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-55ff-j47x-6xcq

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

2%
Низкий
около 4 лет назад
github логотип
GHSA-rvxr-qvvc-m3g5

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.

1%
Низкий
около 4 лет назад
github логотип
GHSA-ff73-cwc3-6v5j

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

2%
Низкий
около 4 лет назад
github логотип
GHSA-cfp2-8mw9-wg68

An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-w772-f4fj-g5xq

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4. It has Insecure Permissions.

1%
Низкий
около 4 лет назад
github логотип
GHSA-645m-h3pw-m72w

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться