Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.618.718.8202520262027

Недавние уязвимости Gitlab

Количество 5 336

debian логотип

CVE-2019-13011

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12 ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-13010

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It allows Uncontrolled Resource Consumption.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2019-13010

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0. ...

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2019-13009

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It has Incorrect Access Control.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-13009

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.2 ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-13007

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.11 through 12.0.2. When an admin enabled one of the service templates, it was triggering an action that leads to resource depletion. It allows Uncontrolled Resource Consumption.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2019-13007

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2019-13121

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-13011

почти 6 лет назад

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-13007

почти 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.11 through 12.0.2. When an admin enabled one of the service templates, it was triggering an action that leads to resource depletion. It allows Uncontrolled Resource Consumption.

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2019-13011

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12 ...

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-13010

An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It allows Uncontrolled Resource Consumption.

CVSS3: 5.9
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-13010

An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0. ...

CVSS3: 5.9
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-13009

An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It has Incorrect Access Control.

CVSS3: 6.5
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-13009

An issue was discovered in GitLab Community and Enterprise Edition 9.2 ...

CVSS3: 6.5
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-13007

An issue was discovered in GitLab Community and Enterprise Edition 11.11 through 12.0.2. When an admin enabled one of the service templates, it was triggering an action that leads to resource depletion. It allows Uncontrolled Resource Consumption.

CVSS3: 4.9
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-13007

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 4.9
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-13121

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-13011

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-13007

An issue was discovered in GitLab Community and Enterprise Edition 11.11 through 12.0.2. When an admin enabled one of the service templates, it was triggering an action that leads to resource depletion. It allows Uncontrolled Resource Consumption.

CVSS3: 4.9
0%
Низкий
почти 6 лет назад

Уязвимостей на страницу


Поделиться