Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2022-1175

больше 4 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.4 be ...

CVSS3: 8.7
EPSS: Высокий
nvd логотип

CVE-2022-1174

больше 4 лет назад

A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-1174

больше 4 лет назад

A potential DoS vulnerability was discovered in Gitlab CE/EE versions ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1162

больше 4 лет назад

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

CVSS3: 9.1
EPSS: Высокий
debian логотип

CVE-2022-1162

больше 4 лет назад

A hardcoded password was set for accounts registered using an OmniAuth ...

CVSS3: 9.1
EPSS: Высокий
nvd логотип

CVE-2022-1148

больше 4 лет назад

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-1148

больше 4 лет назад

Improper authorization in GitLab Pages included with GitLab CE/EE affe ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-1121

больше 4 лет назад

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-1121

больше 4 лет назад

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/E ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-1120

больше 4 лет назад

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2022-1175

Improper neutralization of user input in GitLab CE/EE versions 14.4 be ...

CVSS3: 8.7
82%
Высокий
больше 4 лет назад
nvd логотип
CVE-2022-1174

A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-1174

A potential DoS vulnerability was discovered in Gitlab CE/EE versions ...

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-1162

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

CVSS3: 9.1
76%
Высокий
больше 4 лет назад
debian логотип
CVE-2022-1162

A hardcoded password was set for accounts registered using an OmniAuth ...

CVSS3: 9.1
76%
Высокий
больше 4 лет назад
nvd логотип
CVE-2022-1148

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-1148

Improper authorization in GitLab Pages included with GitLab CE/EE affe ...

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-1121

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-1121

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/E ...

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-1120

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 4.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться