Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 871
CVE-2021-39869
In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
CVE-2021-39869
In all versions of GitLab CE/EE since version 8.9, project exports may ...
CVE-2021-39867
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
CVE-2021-39867
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vu ...
CVE-2021-39866
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
CVE-2021-39866
A business logic error in the project deletion process in GitLab 13.6 ...
CVE-2021-39894
In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.
CVE-2021-39869
In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
CVE-2021-39872
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
CVE-2021-39888
In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2021-39869 In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project. | CVSS3: 6.5 | 1% Низкий | почти 5 лет назад | |
CVE-2021-39869 In all versions of GitLab CE/EE since version 8.9, project exports may ... | CVSS3: 6.5 | 1% Низкий | почти 5 лет назад | |
CVE-2021-39867 In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks. | CVSS3: 6.5 | 1% Низкий | почти 5 лет назад | |
CVE-2021-39867 In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vu ... | CVSS3: 6.5 | 1% Низкий | почти 5 лет назад | |
CVE-2021-39866 A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens. | CVSS3: 5.4 | 1% Низкий | почти 5 лет назад | |
CVE-2021-39866 A business logic error in the project deletion process in GitLab 13.6 ... | CVSS3: 5.4 | 1% Низкий | почти 5 лет назад | |
CVE-2021-39894 In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks. | CVSS3: 5.4 | 1% Низкий | почти 5 лет назад | |
CVE-2021-39869 In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project. | CVSS3: 6.5 | 1% Низкий | почти 5 лет назад | |
CVE-2021-39872 In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration. | CVSS3: 6.5 | 1% Низкий | почти 5 лет назад | |
CVE-2021-39888 In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates. | CVSS3: 4.3 | 1% Низкий | почти 5 лет назад |
Уязвимостей на страницу