Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Количество 5 336
CVE-2019-12444
An issue was discovered in GitLab Community and Enterprise Edition 8.9 ...
CVE-2019-12443
An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks.
CVE-2019-12443
An issue was discovered in GitLab Community and Enterprise Edition 10. ...
CVE-2019-12442
An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.
CVE-2019-12442
An issue was discovered in GitLab Enterprise Edition 11.7 through 11.1 ...
CVE-2019-12441
An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.
CVE-2019-12441
An issue was discovered in GitLab Community and Enterprise Edition 8.4 ...
CVE-2019-13004
An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2).
CVE-2019-12442
An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.
CVE-2019-13003
An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Uncontrolled Resource Consumption.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2019-12444 An issue was discovered in GitLab Community and Enterprise Edition 8.9 ... | CVSS3: 6.1 | 0% Низкий | почти 6 лет назад | |
CVE-2019-12443 An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks. | CVSS3: 9.8 | 0% Низкий | почти 6 лет назад | |
CVE-2019-12443 An issue was discovered in GitLab Community and Enterprise Edition 10. ... | CVSS3: 9.8 | 0% Низкий | почти 6 лет назад | |
CVE-2019-12442 An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics. | CVSS3: 6.1 | 0% Низкий | почти 6 лет назад | |
CVE-2019-12442 An issue was discovered in GitLab Enterprise Edition 11.7 through 11.1 ... | CVSS3: 6.1 | 0% Низкий | почти 6 лет назад | |
CVE-2019-12441 An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control. | CVSS3: 7.5 | 0% Низкий | почти 6 лет назад | |
CVE-2019-12441 An issue was discovered in GitLab Community and Enterprise Edition 8.4 ... | CVSS3: 7.5 | 0% Низкий | почти 6 лет назад | |
CVE-2019-13004 An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2). | CVSS3: 5.3 | 0% Низкий | почти 6 лет назад | |
CVE-2019-12442 An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics. | CVSS3: 6.1 | 0% Низкий | почти 6 лет назад | |
CVE-2019-13003 An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Uncontrolled Resource Consumption. | CVSS3: 7.5 | 0% Низкий | почти 6 лет назад |
Уязвимостей на страницу