Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Количество 5 332
CVE-2020-8795
In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.
CVE-2019-12825
Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.
CVE-2019-12825
Unauthorized Access to the Container Registry of other groups was disc ...
CVE-2019-12825
Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.
CVE-2019-15594
GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.
CVE-2019-15594
GitLab 11.8 and later contains a security vulnerability that allows a ...
CVE-2019-15592
GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.
CVE-2019-15592
GitLab 12.2.2 and below contains a security vulnerability that allows ...
CVE-2019-15592
GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.
CVE-2019-15594
GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2020-8795 In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users. | CVSS3: 7.5 | 0% Низкий | почти 6 лет назад | |
CVE-2019-12825 Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo. | CVSS3: 4.3 | 0% Низкий | почти 6 лет назад | |
CVE-2019-12825 Unauthorized Access to the Container Registry of other groups was disc ... | CVSS3: 4.3 | 0% Низкий | почти 6 лет назад | |
CVE-2019-12825 Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo. | CVSS3: 4.3 | 0% Низкий | почти 6 лет назад | |
CVE-2019-15594 GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint. | CVSS3: 4.3 | 0% Низкий | почти 6 лет назад | |
CVE-2019-15594 GitLab 11.8 and later contains a security vulnerability that allows a ... | CVSS3: 4.3 | 0% Низкий | почти 6 лет назад | |
CVE-2019-15592 GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline. | CVSS3: 4.3 | 0% Низкий | почти 6 лет назад | |
CVE-2019-15592 GitLab 12.2.2 and below contains a security vulnerability that allows ... | CVSS3: 4.3 | 0% Низкий | почти 6 лет назад | |
CVE-2019-15592 GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline. | CVSS3: 4.3 | 0% Низкий | почти 6 лет назад | |
CVE-2019-15594 GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint. | CVSS3: 4.3 | 0% Низкий | почти 6 лет назад |
Уязвимостей на страницу