Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-rhvj-gv4v-wvcv

около 4 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9r89-5vm4-vcr8

около 4 лет назад

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-6gjc-rr77-h8h6

около 4 лет назад

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-j365-62px-vjjv

около 4 лет назад

Jenkins GitLab Plugin Cross-Site Request Forgery vulnerability

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-923w-9p3x-hmgw

около 4 лет назад

Jenkins GitLab Plugin missing permission checks

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2f58-3p8j-4mx4

около 4 лет назад

Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2h7w-85g4-9cx4

около 4 лет назад

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-chvg-47qc-prxj

около 4 лет назад

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-1423

около 4 лет назад

Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2022-1423

около 4 лет назад

Improper access control in the CI/CD cache mechanism in GitLab CE/EE a ...

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-rhvj-gv4v-wvcv

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-9r89-5vm4-vcr8

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-6gjc-rr77-h8h6

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-j365-62px-vjjv

Jenkins GitLab Plugin Cross-Site Request Forgery vulnerability

CVSS3: 8
1%
Низкий
около 4 лет назад
github логотип
GHSA-923w-9p3x-hmgw

Jenkins GitLab Plugin missing permission checks

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2f58-3p8j-4mx4

Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2h7w-85g4-9cx4

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-chvg-47qc-prxj

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

CVSS3: 7.5
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1423

Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches

CVSS3: 7.1
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1423

Improper access control in the CI/CD cache mechanism in GitLab CE/EE a ...

CVSS3: 7.1
1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться