Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2022-0093

больше 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-0093

больше 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-0090

больше 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-0090

больше 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-39946

больше 4 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2021-39946

больше 4 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.3 to ...

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2021-39942

больше 4 лет назад

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39942

больше 4 лет назад

A denial of service vulnerability in GitLab CE/EE affecting all versio ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39927

больше 4 лет назад

Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and between 14.6.0 and 14.6.1 would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configured to run on a port other than 80 or 443

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2021-39927

больше 4 лет назад

Server side request forgery protections in GitLab CE/EE versions betwe ...

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-0093

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

CVSS3: 3.5
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-0093

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 3.5
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-0090

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-0090

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39946

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

CVSS3: 8.7
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39946

Improper neutralization of user input in GitLab CE/EE versions 14.3 to ...

CVSS3: 8.7
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39942

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39942

A denial of service vulnerability in GitLab CE/EE affecting all versio ...

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39927

Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and between 14.6.0 and 14.6.1 would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configured to run on a port other than 80 or 443

CVSS3: 3.5
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39927

Server side request forgery protections in GitLab CE/EE versions betwe ...

CVSS3: 3.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться