Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

debian логотип

CVE-2021-22245

почти 5 лет назад

Improper validation of commit author in GitLab CE/EE affecting all ver ...

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2021-22244

почти 5 лет назад

Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2021-22244

почти 5 лет назад

Improper authorization in the vulnerability report feature in GitLab E ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2021-22243

почти 5 лет назад

Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group.

CVSS3: 5
EPSS: Низкий
debian логотип

CVE-2021-22243

почти 5 лет назад

Under specialized conditions, GitLab CE/EE versions starting 7.10 may ...

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2021-22242

почти 5 лет назад

Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

CVSS3: 8.7
EPSS: Средний
debian логотип

CVE-2021-22242

почти 5 лет назад

Insufficient input sanitization in Mermaid markdown in GitLab CE/EE ve ...

CVSS3: 8.7
EPSS: Средний
nvd логотип

CVE-2021-22237

почти 5 лет назад

Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2

CVSS3: 6.6
EPSS: Низкий
debian логотип

CVE-2021-22237

почти 5 лет назад

Under specialized conditions, GitLab may allow a user with an imperson ...

CVSS3: 6.6
EPSS: Низкий
nvd логотип

CVE-2021-22236

почти 5 лет назад

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2021-22245

Improper validation of commit author in GitLab CE/EE affecting all ver ...

CVSS3: 2.7
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22244

Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data

CVSS3: 3.1
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22244

Improper authorization in the vulnerability report feature in GitLab E ...

CVSS3: 3.1
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22243

Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group.

CVSS3: 5
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22243

Under specialized conditions, GitLab CE/EE versions starting 7.10 may ...

CVSS3: 5
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22242

Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

CVSS3: 8.7
64%
Средний
почти 5 лет назад
debian логотип
CVE-2021-22242

Insufficient input sanitization in Mermaid markdown in GitLab CE/EE ve ...

CVSS3: 8.7
64%
Средний
почти 5 лет назад
nvd логотип
CVE-2021-22237

Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2

CVSS3: 6.6
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22237

Under specialized conditions, GitLab may allow a user with an imperson ...

CVSS3: 6.6
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22236

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

CVSS3: 5.5
1%
Низкий
почти 5 лет назад

Уязвимостей на страницу


Поделиться