Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-vx8w-6r69-h5fv

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3cjm-23gg-86mm

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-ffcr-rwf9-9f8f

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2pc6-768q-99h7

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.

EPSS: Низкий
github логотип

GHSA-wxhf-x7mr-5gwp

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure of private milestones, labels, and other information.

EPSS: Низкий
github логотип

GHSA-79gc-8hc2-gp5v

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, commit titles and team member comments could become viewable to users who did not have permission to access these.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-5jcx-pvq7-vfwp

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.

EPSS: Низкий
github логотип

GHSA-89gh-7gfw-7rqp

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1. Insufficient permission checks were being applied when displaying CI results, potentially exposing some CI metrics data to unauthorized users.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-c89r-pq4x-7rmr

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1. The Jira integration contains a SSRF vulnerability as a result of a bypass of the current protection mechanisms against this type of attack, which would allow sending requests to any resources accessible in the local network by the GitLab server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9wrx-mw8f-hx7p

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-vx8w-6r69-h5fv

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-3cjm-23gg-86mm

An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-ffcr-rwf9-9f8f

An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-2pc6-768q-99h7

An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.

2%
Низкий
около 4 лет назад
github логотип
GHSA-wxhf-x7mr-5gwp

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure of private milestones, labels, and other information.

2%
Низкий
около 4 лет назад
github логотип
GHSA-79gc-8hc2-gp5v

An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, commit titles and team member comments could become viewable to users who did not have permission to access these.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-5jcx-pvq7-vfwp

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.

1%
Низкий
около 4 лет назад
github логотип
GHSA-89gh-7gfw-7rqp

An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1. Insufficient permission checks were being applied when displaying CI results, potentially exposing some CI metrics data to unauthorized users.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-c89r-pq4x-7rmr

An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1. The Jira integration contains a SSRF vulnerability as a result of a bypass of the current protection mechanisms against this type of attack, which would allow sending requests to any resources accessible in the local network by the GitLab server.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-9wrx-mw8f-hx7p

An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.

CVSS3: 7.5
2%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться