Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
CVE-2022-1175
Improper neutralization of user input in GitLab CE/EE versions 14.4 be ...
CVE-2022-1174
A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.
CVE-2022-1174
A potential DoS vulnerability was discovered in Gitlab CE/EE versions ...
CVE-2022-1162
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts
CVE-2022-1162
A hardcoded password was set for accounts registered using an OmniAuth ...
CVE-2022-1148
Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites
CVE-2022-1148
Improper authorization in GitLab Pages included with GitLab CE/EE affe ...
CVE-2022-1121
A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.
CVE-2022-1121
A lack of appropriate timeouts in GitLab Pages included in GitLab CE/E ...
CVE-2022-1120
Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2022-1175 Improper neutralization of user input in GitLab CE/EE versions 14.4 be ... | CVSS3: 8.7 | 82% Высокий | больше 4 лет назад | |
CVE-2022-1174 A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc. | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1174 A potential DoS vulnerability was discovered in Gitlab CE/EE versions ... | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1162 A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts | CVSS3: 9.1 | 76% Высокий | больше 4 лет назад | |
CVE-2022-1162 A hardcoded password was set for accounts registered using an OmniAuth ... | CVSS3: 9.1 | 76% Высокий | больше 4 лет назад | |
CVE-2022-1148 Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1148 Improper authorization in GitLab Pages included with GitLab CE/EE affe ... | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1121 A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption. | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1121 A lack of appropriate timeouts in GitLab Pages included in GitLab CE/E ... | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1120 Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration. | CVSS3: 4.8 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу