Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.618.718.8202520262027

Недавние уязвимости Gitlab

Количество 5 336

ubuntu логотип

CVE-2020-10083

почти 6 лет назад

GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2020-10092

почти 6 лет назад

GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-10088

почти 6 лет назад

GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2020-10085

почти 6 лет назад

GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-10535

почти 6 лет назад

GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-10535

почти 6 лет назад

GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote at ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-10535

почти 6 лет назад

GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-13121

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-13121

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0 ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-13011

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2020-10083

GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.

CVSS3: 9.1
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2020-10092

GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.

CVSS3: 6.1
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2020-10088

GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.

CVSS3: 8.1
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2020-10085

GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.

CVSS3: 5.3
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-10535

GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.

CVSS3: 5.3
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-10535

GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote at ...

CVSS3: 5.3
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2020-10535

GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.

CVSS3: 5.3
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-13121

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-13121

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0 ...

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-13011

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад

Уязвимостей на страницу


Поделиться