Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

ubuntu логотип

CVE-2021-39881

почти 5 лет назад

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2021-39889

почти 5 лет назад

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22258

почти 5 лет назад

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22262

почти 5 лет назад

Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2021-22264

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2021-39886

почти 5 лет назад

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2021-39894

почти 5 лет назад

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2021-39894

почти 5 лет назад

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vul ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2021-39893

почти 5 лет назад

A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-39893

почти 5 лет назад

A potential DOS vulnerability was discovered in GitLab starting with v ...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2021-39881

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVSS3: 3.5
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-39889

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22258

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

CVSS3: 4.3
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22262

Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page

CVSS3: 5.4
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22264

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

CVSS3: 6.8
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-39886

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

CVSS3: 2.6
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-39894

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

CVSS3: 5.4
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-39894

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vul ...

CVSS3: 5.4
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-39893

A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

CVSS3: 5.3
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-39893

A potential DOS vulnerability was discovered in GitLab starting with v ...

CVSS3: 5.3
1%
Низкий
почти 5 лет назад

Уязвимостей на страницу


Поделиться