Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2022-0154

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious user to have their GitHub project imported on another GitLab user account.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-0154

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-0152

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the GraphQL API.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-0152

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-0151

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could result in a Denial of Service under specific conditions.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-0151

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-0125

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-0125

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-0124

больше 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-0124

больше 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-0154

An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious user to have their GitHub project imported on another GitLab user account.

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-0154

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-0152

An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the GraphQL API.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-0152

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-0151

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could result in a Denial of Service under specific conditions.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-0151

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-0125

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-0125

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-0124

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-0124

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 4.3
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться