Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.618.718.8202520262027

Недавние уязвимости Gitlab

Количество 5 336

nvd логотип

CVE-2020-13284

больше 5 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2020-13284

больше 5 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2020-13300

больше 5 лет назад

GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.

CVSS3: 8
EPSS: Низкий
ubuntu логотип

CVE-2020-13318

больше 5 лет назад

A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2020-13316

больше 5 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2020-13284

больше 5 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2020-13299

больше 5 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2020-13287

больше 5 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2020-13289

больше 5 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2020-13286

больше 5 лет назад

For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2020-13284

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-13284

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ...

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-13300

GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.

CVSS3: 8
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-13318

A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.

CVSS3: 6.4
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-13316

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.

CVSS3: 5.4
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-13284

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-13299

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.

CVSS3: 8.1
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-13287

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-13289

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.

CVSS3: 5.4
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-13286

For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.

CVSS3: 6.4
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу


Поделиться