Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Количество 5 336
CVE-2020-13303
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project.
CVE-2020-13307
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user to maintain their access.
CVE-2020-13308
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance.
CVE-2020-13315
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not restricting the amount of results one could request, potentially resulting in a denial of service.
CVE-2020-13315
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ...
CVE-2020-13310
A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the gitlab-runner process crash by sending malformed queries, resulting in a denial of service.
CVE-2020-13310
A vulnerability was discovered in GitLab runner versions before 13.1.3 ...
CVE-2020-13309
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature.
CVE-2020-13309
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ...
CVE-2020-13306
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abused to perform denial of service attacks due to the lack of rate limitation.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2020-13303 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project. | CVSS3: 7.1 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13307 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user to maintain their access. | CVSS3: 3.8 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13308 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance. | CVSS3: 2.7 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13315 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not restricting the amount of results one could request, potentially resulting in a denial of service. | CVSS3: 3.7 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13315 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ... | CVSS3: 3.7 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13310 A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the gitlab-runner process crash by sending malformed queries, resulting in a denial of service. | CVSS3: 6.5 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13310 A vulnerability was discovered in GitLab runner versions before 13.1.3 ... | CVSS3: 6.5 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13309 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature. | CVSS3: 5.4 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13309 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ... | CVSS3: 5.4 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13306 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abused to perform denial of service attacks due to the lack of rate limitation. | CVSS3: 3.7 | 0% Низкий | больше 5 лет назад |
Уязвимостей на страницу