Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2022-1193

больше 4 лет назад

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1157

больше 4 лет назад

Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2022-1157

больше 4 лет назад

Missing sanitization of logged exception messages in all versions prio ...

CVSS3: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2022-1157

больше 4 лет назад

Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

CVSS3: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2022-1193

больше 4 лет назад

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-rq9r-r987-7r36

больше 4 лет назад

Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-q242-rh63-p6m2

больше 4 лет назад

An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-5733-m8xv-f92m

больше 4 лет назад

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-66xf-5qxv-jmgr

больше 4 лет назад

Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4fff-jcr9-g646

больше 4 лет назад

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2022-1193

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, ...

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-1157

Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

CVSS3: 2.6
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-1157

Missing sanitization of logged exception messages in all versions prio ...

CVSS3: 2.6
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2022-1157

Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

CVSS3: 2.6
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2022-1193

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-rq9r-r987-7r36

Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-q242-rh63-p6m2

An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-5733-m8xv-f92m

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-66xf-5qxv-jmgr

Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4fff-jcr9-g646

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться