Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2021-22263

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2021-22263

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2021-22263

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2021-39880

почти 5 лет назад

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-39880

почти 5 лет назад

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-39880

почти 5 лет назад

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-39891

почти 5 лет назад

In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2021-39891

почти 5 лет назад

In all versions of GitLab CE/EE since version 8.0, access tokens creat ...

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2021-39889

почти 5 лет назад

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39889

почти 5 лет назад

In all versions of GitLab EE since version 14.1, due to an insecure di ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2021-22263

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

CVSS3: 5.5
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22263

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.5
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22263

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

CVSS3: 5.5
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-39880

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.

CVSS3: 6.5
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-39880

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem ...

CVSS3: 6.5
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-39880

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.

CVSS3: 6.5
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-39891

In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

CVSS3: 5.9
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-39891

In all versions of GitLab CE/EE since version 8.0, access tokens creat ...

CVSS3: 5.9
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-39889

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-39889

In all versions of GitLab EE since version 14.1, due to an insecure di ...

CVSS3: 4.3
1%
Низкий
почти 5 лет назад

Уязвимостей на страницу


Поделиться