Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 871

nvd логотип

CVE-2022-1413

около 4 лет назад

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-1413

около 4 лет назад

Missing input masking in GitLab CE/EE affecting all versions starting ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2022-1413

около 4 лет назад

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2022-1416

около 4 лет назад

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1423

около 4 лет назад

Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-5phj-qv74-pv4w

около 4 лет назад

Missing permission check in Jenkins GitLab Plugin

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2022-03706

около 4 лет назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с недостатками контроля доступа, позволяющая нарушителю получить несанкционированный доступ к ограниченным функциям

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2022-30955

около 4 лет назад

Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v9h3-mqgc-w575

около 4 лет назад

GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.

EPSS: Низкий
github логотип

GHSA-x5gq-3gjr-236f

около 4 лет назад

Cross-site scripting (XSS) vulnerability in GitLab Enterprise Edition (EE) 6.6.0 before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-1413

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

CVSS3: 5.4
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1413

Missing input masking in GitLab CE/EE affecting all versions starting ...

CVSS3: 5.4
1%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1413

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

CVSS3: 5.4
1%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1416

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

CVSS3: 4.3
1%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1423

Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches

CVSS3: 7.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-5phj-qv74-pv4w

Missing permission check in Jenkins GitLab Plugin

CVSS3: 4.3
1%
Низкий
около 4 лет назад
fstec логотип
BDU:2022-03706

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с недостатками контроля доступа, позволяющая нарушителю получить несанкционированный доступ к ограниченным функциям

CVSS3: 2.7
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-30955

Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-v9h3-mqgc-w575

GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.

2%
Низкий
около 4 лет назад
github логотип
GHSA-x5gq-3gjr-236f

Cross-site scripting (XSS) vulnerability in GitLab Enterprise Edition (EE) 6.6.0 before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться