Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 943
CVE-2022-0154
An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious user to have their GitHub project imported on another GitLab user account.
CVE-2022-0154
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2022-0152
An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the GraphQL API.
CVE-2022-0152
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2022-0151
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could result in a Denial of Service under specific conditions.
CVE-2022-0151
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2022-0125
An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.
CVE-2022-0125
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2022-0124
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.
CVE-2022-0124
An issue has been discovered affecting GitLab versions prior to 14.4.5 ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2022-0154 An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious user to have their GitHub project imported on another GitLab user account. | CVSS3: 7.5 | 0% Низкий | больше 4 лет назад | |
CVE-2022-0154 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 7.5 | 0% Низкий | больше 4 лет назад | |
CVE-2022-0152 An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the GraphQL API. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0152 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0151 An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could result in a Denial of Service under specific conditions. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0151 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0125 An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project. | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0125 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0124 An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack. | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0124 An issue has been discovered affecting GitLab versions prior to 14.4.5 ... | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу