Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-wx2f-993h-v22p

около 4 лет назад

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8c6r-xvww-2p23

около 4 лет назад

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2w2f-9xfg-pc7q

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-c459-gw6c-ch4j

около 4 лет назад

GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-fvw3-2rq4-x8qv

около 4 лет назад

GitLab Community and Enterprise Edition before 11.3.14, 11.4.x before 11.4.12, and 11.5.x before 11.5.5 allows Directory Traversal.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2358-4vrj-w4hc

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 3 of 5).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4w7w-4ppq-m6f2

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows CSRF.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-vwxf-55xh-p3xf

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 5 of 5).

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-4j42-wq8q-c389

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-533c-ppxj-mjqj

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 2 of 2). The user status field contains a lack of input validation and output encoding that results in a persistent XSS.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-wx2f-993h-v22p

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-8c6r-xvww-2p23

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2w2f-9xfg-pc7q

An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-c459-gw6c-ch4j

GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-fvw3-2rq4-x8qv

GitLab Community and Enterprise Edition before 11.3.14, 11.4.x before 11.4.12, and 11.5.x before 11.5.5 allows Directory Traversal.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2358-4vrj-w4hc

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 3 of 5).

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-4w7w-4ppq-m6f2

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows CSRF.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-vwxf-55xh-p3xf

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 5 of 5).

CVSS3: 3.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-4j42-wq8q-c389

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.

CVSS3: 10
2%
Низкий
около 4 лет назад
github логотип
GHSA-533c-ppxj-mjqj

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 2 of 2). The user status field contains a lack of input validation and output encoding that results in a persistent XSS.

CVSS3: 6.1
1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться