Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Количество 5 336
CVE-2020-10083
GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.
CVE-2020-10092
GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.
CVE-2020-10088
GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.
CVE-2020-10085
GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.
CVE-2020-10535
GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.
CVE-2020-10535
GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote at ...
CVE-2020-10535
GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.
CVE-2019-13121
An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.
CVE-2019-13121
An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0 ...
CVE-2019-13011
An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2020-10083 GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied. | CVSS3: 9.1 | 0% Низкий | почти 6 лет назад | |
CVE-2020-10092 GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration. | CVSS3: 6.1 | 0% Низкий | почти 6 лет назад | |
CVE-2020-10088 GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level. | CVSS3: 8.1 | 0% Низкий | почти 6 лет назад | |
CVE-2020-10085 GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles. | CVSS3: 5.3 | 0% Низкий | почти 6 лет назад | |
CVE-2020-10535 GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address. | CVSS3: 5.3 | 0% Низкий | почти 6 лет назад | |
CVE-2020-10535 GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote at ... | CVSS3: 5.3 | 0% Низкий | почти 6 лет назад | |
CVE-2020-10535 GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address. | CVSS3: 5.3 | 0% Низкий | почти 6 лет назад | |
CVE-2019-13121 An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control. | CVSS3: 7.5 | 0% Низкий | почти 6 лет назад | |
CVE-2019-13121 An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0 ... | CVSS3: 7.5 | 0% Низкий | почти 6 лет назад | |
CVE-2019-13011 An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity. | CVSS3: 4.3 | 0% Низкий | почти 6 лет назад |
Уязвимостей на страницу