Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2021-22170

больше 4 лет назад

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows ...

CVSS3: 6.2
EPSS: Низкий
ubuntu логотип

CVE-2021-39890

больше 4 лет назад

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2021-22170

больше 4 лет назад

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2021-39913

почти 5 лет назад

Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2021-39913

почти 5 лет назад

Accidental logging of system root password in the migration log in all ...

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2021-39912

почти 5 лет назад

A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-39912

почти 5 лет назад

A potential DoS vulnerability was discovered in GitLab CE/EE starting ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-39911

почти 5 лет назад

An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers

CVSS3: 1.7
EPSS: Низкий
debian логотип

CVE-2021-39911

почти 5 лет назад

An improper access control flaw in all versions of GitLab CE/EE starti ...

CVSS3: 1.7
EPSS: Низкий
nvd логотип

CVE-2021-39909

почти 5 лет назад

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2021-22170

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows ...

CVSS3: 6.2
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39890

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

CVSS3: 3.1
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22170

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content

CVSS3: 6.2
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39913

Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges

CVSS3: 4.4
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-39913

Accidental logging of system root password in the migration log in all ...

CVSS3: 4.4
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-39912

A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion.

CVSS3: 5.3
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-39912

A potential DoS vulnerability was discovered in GitLab CE/EE starting ...

CVSS3: 5.3
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-39911

An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers

CVSS3: 1.7
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-39911

An improper access control flaw in all versions of GitLab CE/EE starti ...

CVSS3: 1.7
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-39909

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
1%
Низкий
почти 5 лет назад

Уязвимостей на страницу


Поделиться