Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Количество 5 336
CVE-2019-13011
An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12 ...
CVE-2019-13010
An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It allows Uncontrolled Resource Consumption.
CVE-2019-13010
An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0. ...
CVE-2019-13009
An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It has Incorrect Access Control.
CVE-2019-13009
An issue was discovered in GitLab Community and Enterprise Edition 9.2 ...
CVE-2019-13007
An issue was discovered in GitLab Community and Enterprise Edition 11.11 through 12.0.2. When an admin enabled one of the service templates, it was triggering an action that leads to resource depletion. It allows Uncontrolled Resource Consumption.
CVE-2019-13007
An issue was discovered in GitLab Community and Enterprise Edition 11. ...
CVE-2019-13121
An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.
CVE-2019-13011
An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.
CVE-2019-13007
An issue was discovered in GitLab Community and Enterprise Edition 11.11 through 12.0.2. When an admin enabled one of the service templates, it was triggering an action that leads to resource depletion. It allows Uncontrolled Resource Consumption.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2019-13011 An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12 ... | CVSS3: 4.3 | 0% Низкий | почти 6 лет назад | |
CVE-2019-13010 An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It allows Uncontrolled Resource Consumption. | CVSS3: 5.9 | 0% Низкий | почти 6 лет назад | |
CVE-2019-13010 An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0. ... | CVSS3: 5.9 | 0% Низкий | почти 6 лет назад | |
CVE-2019-13009 An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It has Incorrect Access Control. | CVSS3: 6.5 | 0% Низкий | почти 6 лет назад | |
CVE-2019-13009 An issue was discovered in GitLab Community and Enterprise Edition 9.2 ... | CVSS3: 6.5 | 0% Низкий | почти 6 лет назад | |
CVE-2019-13007 An issue was discovered in GitLab Community and Enterprise Edition 11.11 through 12.0.2. When an admin enabled one of the service templates, it was triggering an action that leads to resource depletion. It allows Uncontrolled Resource Consumption. | CVSS3: 4.9 | 0% Низкий | почти 6 лет назад | |
CVE-2019-13007 An issue was discovered in GitLab Community and Enterprise Edition 11. ... | CVSS3: 4.9 | 0% Низкий | почти 6 лет назад | |
CVE-2019-13121 An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control. | CVSS3: 7.5 | 0% Низкий | почти 6 лет назад | |
CVE-2019-13011 An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity. | CVSS3: 4.3 | 0% Низкий | почти 6 лет назад | |
CVE-2019-13007 An issue was discovered in GitLab Community and Enterprise Edition 11.11 through 12.0.2. When an admin enabled one of the service templates, it was triggering an action that leads to resource depletion. It allows Uncontrolled Resource Consumption. | CVSS3: 4.9 | 0% Низкий | почти 6 лет назад |
Уязвимостей на страницу