Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2022-0373

больше 4 лет назад

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39908

больше 4 лет назад

In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-39908

больше 4 лет назад

In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-39908

больше 4 лет назад

In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-0373

больше 4 лет назад

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-0741

больше 4 лет назад

Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables via specially crafted email addresses.

CVSS3: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2022-0489

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-0425

больше 4 лет назад

A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2022-0390

больше 4 лет назад

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2022-02365

больше 4 лет назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 8.7
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2022-0373

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 ...

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39908

In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39908

In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all ...

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39908

In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2022-0373

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2022-0741

Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables via specially crafted email addresses.

CVSS3: 5.8
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2022-0489

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.

CVSS3: 3.5
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2022-0425

A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2022-0390

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
fstec логотип
BDU:2022-02365

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 8.7
82%
Высокий
больше 4 лет назад

Уязвимостей на страницу


Поделиться