Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

fstec логотип

BDU:2022-01820

больше 4 лет назад

Уязвимость программной платформы для совместной работы над кодом GitLab, связанная с установкой предопределённых (hardcoded) паролей для учётных записей, зарегистрированных с использованием провайдера OmniAuth (OAuth, LDAP и SAML), позволяющая нарушителю получить доступ к учетным записям пользователей

CVSS3: 9.1
EPSS: Высокий
nvd логотип

CVE-2022-1190

больше 4 лет назад

Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.

CVSS3: 8.7
EPSS: Высокий
debian логотип

CVE-2022-1190

больше 4 лет назад

Improper handling of user input in GitLab CE/EE versions 8.3 prior to ...

CVSS3: 8.7
EPSS: Высокий
nvd логотип

CVE-2022-1189

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 that allowed for an unauthorised user to read the the approval rules of a private project.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2022-1189

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-1188

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2022-1188

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2022-1185

больше 4 лет назад

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-1185

больше 4 лет назад

A denial of service vulnerability when rendering RDoc files in GitLab ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-1175

больше 4 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

CVSS3: 8.7
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
fstec логотип
BDU:2022-01820

Уязвимость программной платформы для совместной работы над кодом GitLab, связанная с установкой предопределённых (hardcoded) паролей для учётных записей, зарегистрированных с использованием провайдера OmniAuth (OAuth, LDAP и SAML), позволяющая нарушителю получить доступ к учетным записям пользователей

CVSS3: 9.1
76%
Высокий
больше 4 лет назад
nvd логотип
CVE-2022-1190

Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.

CVSS3: 8.7
87%
Высокий
больше 4 лет назад
debian логотип
CVE-2022-1190

Improper handling of user input in GitLab CE/EE versions 8.3 prior to ...

CVSS3: 8.7
87%
Высокий
больше 4 лет назад
nvd логотип
CVE-2022-1189

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 that allowed for an unauthorised user to read the the approval rules of a private project.

CVSS3: 3.1
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-1189

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.1
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-1188

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.

CVSS3: 3.7
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-1188

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.7
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-1185

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-1185

A denial of service vulnerability when rendering RDoc files in GitLab ...

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-1175

Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

CVSS3: 8.7
82%
Высокий
больше 4 лет назад

Уязвимостей на страницу


Поделиться