Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

ubuntu логотип

CVE-2021-22221

около 5 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-22218

около 5 лет назад

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2021-22218

около 5 лет назад

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all ve ...

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2021-22215

около 5 лет назад

An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-22215

около 5 лет назад

An information disclosure vulnerability in GitLab EE versions 13.11 an ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2021-22218

около 5 лет назад

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2021-22214

около 5 лет назад

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

CVSS3: 6.8
EPSS: Средний
debian логотип

CVE-2021-22214

около 5 лет назад

When requests to the internal network for webhooks are enabled, a serv ...

CVSS3: 6.8
EPSS: Средний
ubuntu логотип

CVE-2021-22214

около 5 лет назад

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

CVSS3: 6.8
EPSS: Средний
fstec логотип

BDU:2022-01867

около 5 лет назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2021-22221

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired

CVSS3: 6.5
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-22218

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
0%
Низкий
около 5 лет назад
debian логотип
CVE-2021-22218

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all ve ...

CVSS3: 2.6
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-22215

An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects

CVSS3: 7.5
1%
Низкий
около 5 лет назад
debian логотип
CVE-2021-22215

An information disclosure vulnerability in GitLab EE versions 13.11 an ...

CVSS3: 7.5
1%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2021-22218

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-22214

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

CVSS3: 6.8
28%
Средний
около 5 лет назад
debian логотип
CVE-2021-22214

When requests to the internal network for webhooks are enabled, a serv ...

CVSS3: 6.8
28%
Средний
около 5 лет назад
ubuntu логотип
CVE-2021-22214

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

CVSS3: 6.8
28%
Средний
около 5 лет назад
fstec логотип
BDU:2022-01867

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

CVSS3: 5.4
1%
Низкий
около 5 лет назад

Уязвимостей на страницу


Поделиться