Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

nvd логотип

CVE-2021-22228

около 5 лет назад

An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2. Improper access control allows unauthorised users to access project details using Graphql.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-22228

около 5 лет назад

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-22223

около 5 лет назад

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2021-22223

около 5 лет назад

Client-Side code injection through Feature Flag name in GitLab CE/EE s ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2021-22223

около 5 лет назад

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2021-22228

около 5 лет назад

An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2. Improper access control allows unauthorised users to access project details using Graphql.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-22232

около 5 лет назад

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2021-22232

около 5 лет назад

HTML injection was possible via the full name field before versions 13 ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2021-22229

около 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2021-22229

около 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2021-22228

An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2. Improper access control allows unauthorised users to access project details using Graphql.

CVSS3: 6.5
1%
Низкий
около 5 лет назад
debian логотип
CVE-2021-22228

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 6.5
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-22223

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

CVSS3: 6.1
1%
Низкий
около 5 лет назад
debian логотип
CVE-2021-22223

Client-Side code injection through Feature Flag name in GitLab CE/EE s ...

CVSS3: 6.1
1%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2021-22223

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

CVSS3: 6.1
1%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2021-22228

An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2. Improper access control allows unauthorised users to access project details using Graphql.

CVSS3: 6.5
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-22232

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

CVSS3: 3.5
1%
Низкий
около 5 лет назад
debian логотип
CVE-2021-22232

HTML injection was possible via the full name field before versions 13 ...

CVSS3: 3.5
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-22229

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member.

CVSS3: 5.9
1%
Низкий
около 5 лет назад
debian логотип
CVE-2021-22229

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.9
1%
Низкий
около 5 лет назад

Уязвимостей на страницу


Поделиться