Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2021-39871

почти 5 лет назад

In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39871

почти 5 лет назад

In all versions of GitLab CE/EE since version 13.0, an instance that h ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39868

почти 5 лет назад

In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39868

почти 5 лет назад

In all versions of GitLab CE/EE since version 8.12, an authenticated l ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-22259

почти 5 лет назад

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-22259

почти 5 лет назад

A potential DOS vulnerability was discovered in GitLab EE starting wit ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39879

почти 5 лет назад

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS3: 2.2
EPSS: Низкий
ubuntu логотип

CVE-2021-39885

почти 5 лет назад

A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2021-22259

почти 5 лет назад

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39896

почти 5 лет назад

In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues.

CVSS3: 3.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2021-39871

In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call.

CVSS3: 4.3
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-39871

In all versions of GitLab CE/EE since version 13.0, an instance that h ...

CVSS3: 4.3
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-39868

In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.

CVSS3: 4.3
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-39868

In all versions of GitLab CE/EE since version 8.12, an authenticated l ...

CVSS3: 4.3
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22259

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

CVSS3: 4.3
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22259

A potential DOS vulnerability was discovered in GitLab EE starting wit ...

CVSS3: 4.3
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-39879

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS3: 2.2
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-39885

A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names

CVSS3: 8.7
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22259

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

CVSS3: 4.3
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-39896

In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues.

CVSS3: 3.8
1%
Низкий
почти 5 лет назад

Уязвимостей на страницу


Поделиться