Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
CVE-2022-1120
Missing filtering in an error message in GitLab CE/EE affecting all ve ...
CVE-2022-1111
A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages
CVE-2022-1111
A business logic error in Project Import in GitLab CE/EE versions 14.9 ...
CVE-2022-1105
An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled
CVE-2022-1105
An improper access control vulnerability in GitLab CE/EE affecting all ...
CVE-2022-1100
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.
CVE-2022-1100
A potential DOS vulnerability was discovered in GitLab CE/EE affecting ...
CVE-2022-1099
Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab
CVE-2022-1099
Adding a very large number of tags to a runner in GitLab CE/EE affecti ...
CVE-2022-0740
Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2022-1120 Missing filtering in an error message in GitLab CE/EE affecting all ve ... | CVSS3: 4.8 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1111 A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages | CVSS3: 2.4 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1111 A business logic error in Project Import in GitLab CE/EE versions 14.9 ... | CVSS3: 2.4 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1105 An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1105 An improper access control vulnerability in GitLab CE/EE affecting all ... | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1100 A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage. | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1100 A potential DOS vulnerability was discovered in GitLab CE/EE affecting ... | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1099 Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1099 Adding a very large number of tags to a runner in GitLab CE/EE affecti ... | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0740 Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches. | CVSS3: 3.1 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу