Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2021-39936

больше 4 лет назад

Improper access control in GitLab CE/EE affecting all versions startin ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2021-39935

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

CVSS3: 6.8
EPSS: Средний
debian логотип

CVE-2021-39935

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.8
EPSS: Средний
nvd логотип

CVE-2021-39934

больше 4 лет назад

Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39934

больше 4 лет назад

Improper access control allows any project member to retrieve the serv ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39933

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39933

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39932

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for users reviewing code changes.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39932

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39931

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2021-39936

Improper access control in GitLab CE/EE affecting all versions startin ...

CVSS3: 3.5
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39935

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

CVSS3: 6.8
36%
Средний
больше 4 лет назад
debian логотип
CVE-2021-39935

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.8
36%
Средний
больше 4 лет назад
nvd логотип
CVE-2021-39934

Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39934

Improper access control allows any project member to retrieve the serv ...

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39933

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39933

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39932

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for users reviewing code changes.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39932

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39931

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.

CVSS3: 3.1
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться