Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2021-22261

почти 5 лет назад

A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2021-22261

почти 5 лет назад

A stored Cross-Site Scripting vulnerability in the Jira integration in ...

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2021-22258

почти 5 лет назад

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-22258

почти 5 лет назад

The project import/export feature in GitLab 8.9 and greater could be u ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-22257

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-22257

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22257

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22261

почти 5 лет назад

A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39891

почти 5 лет назад

In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2021-39870

почти 5 лет назад

In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2021-22261

A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 7.3
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22261

A stored Cross-Site Scripting vulnerability in the Jira integration in ...

CVSS3: 7.3
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22258

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

CVSS3: 4.3
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22258

The project import/export feature in GitLab 8.9 and greater could be u ...

CVSS3: 4.3
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22257

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.

CVSS3: 5.3
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22257

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.3
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22257

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.

CVSS3: 5.3
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22261

A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 7.3
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-39891

In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

CVSS3: 5.9
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-39870

In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.

CVSS3: 4.3
1%
Низкий
почти 5 лет назад

Уязвимостей на страницу


Поделиться