Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-75xf-j8f2-9vxq

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-c9xg-h9c4-4vv6

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could result in a Denial of Service under specific conditions.

EPSS: Низкий
github логотип

GHSA-wggh-9jhq-9h7x

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the GraphQL API.

EPSS: Низкий
github логотип

GHSA-jm36-4mv9-x2pw

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-c8m7-c9rp-w2g3

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious user to have their GitHub project imported on another GitLab user account.

EPSS: Низкий
github логотип

GHSA-66vj-p7rx-6jrr

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.

EPSS: Низкий
nvd логотип

CVE-2022-0244

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2022-0244

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2022-0172

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-0172

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-75xf-j8f2-9vxq

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-c9xg-h9c4-4vv6

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could result in a Denial of Service under specific conditions.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-wggh-9jhq-9h7x

An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the GraphQL API.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-jm36-4mv9-x2pw

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-c8m7-c9rp-w2g3

An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious user to have their GitHub project imported on another GitLab user account.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-66vj-p7rx-6jrr

An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.

2%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-0244

An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.

CVSS3: 8.6
2%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-0244

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.6
2%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-0172

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-0172

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться