Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 871

debian логотип

CVE-2022-1174

больше 4 лет назад

A potential DoS vulnerability was discovered in Gitlab CE/EE versions ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1162

больше 4 лет назад

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

CVSS3: 9.1
EPSS: Высокий
debian логотип

CVE-2022-1162

больше 4 лет назад

A hardcoded password was set for accounts registered using an OmniAuth ...

CVSS3: 9.1
EPSS: Высокий
nvd логотип

CVE-2022-1148

больше 4 лет назад

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-1148

больше 4 лет назад

Improper authorization in GitLab Pages included with GitLab CE/EE affe ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-1121

больше 4 лет назад

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-1121

больше 4 лет назад

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/E ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-1120

больше 4 лет назад

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2022-1120

больше 4 лет назад

Missing filtering in an error message in GitLab CE/EE affecting all ve ...

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2022-1111

больше 4 лет назад

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

CVSS3: 2.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2022-1174

A potential DoS vulnerability was discovered in Gitlab CE/EE versions ...

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-1162

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

CVSS3: 9.1
76%
Высокий
больше 4 лет назад
debian логотип
CVE-2022-1162

A hardcoded password was set for accounts registered using an OmniAuth ...

CVSS3: 9.1
76%
Высокий
больше 4 лет назад
nvd логотип
CVE-2022-1148

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-1148

Improper authorization in GitLab Pages included with GitLab CE/EE affe ...

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-1121

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-1121

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/E ...

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-1120

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-1120

Missing filtering in an error message in GitLab CE/EE affecting all ve ...

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-1111

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

CVSS3: 2.4
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться