Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

ubuntu логотип

CVE-2021-39940

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39931

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2021-39918

больше 4 лет назад

Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to a vulnerability which cannot be accessed.

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2021-39919

больше 4 лет назад

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2021-39937

больше 4 лет назад

A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-45jj-6gxc-rh25

больше 4 лет назад

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

EPSS: Низкий
github логотип

GHSA-65v8-8343-jcqr

больше 4 лет назад

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-39890

больше 4 лет назад

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2021-39890

больше 4 лет назад

It was possible to bypass 2FA for LDAP users and access some specific ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2021-22170

больше 4 лет назад

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content

CVSS3: 6.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2021-39940

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39931

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.

CVSS3: 3.1
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39918

Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to a vulnerability which cannot be accessed.

CVSS3: 3.1
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39919

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39937

A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45jj-6gxc-rh25

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-65v8-8343-jcqr

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39890

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

CVSS3: 3.1
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39890

It was possible to bypass 2FA for LDAP users and access some specific ...

CVSS3: 3.1
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22170

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content

CVSS3: 6.2
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться