Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.618.718.8202520262027

Недавние уязвимости Gitlab

Количество 5 332

ubuntu логотип

CVE-2020-8795

почти 6 лет назад

In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-12825

почти 6 лет назад

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-12825

почти 6 лет назад

Unauthorized Access to the Container Registry of other groups was disc ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-12825

почти 6 лет назад

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-15594

почти 6 лет назад

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-15594

почти 6 лет назад

GitLab 11.8 and later contains a security vulnerability that allows a ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-15592

почти 6 лет назад

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-15592

почти 6 лет назад

GitLab 12.2.2 and below contains a security vulnerability that allows ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-15592

почти 6 лет назад

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-15594

почти 6 лет назад

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2020-8795

In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-12825

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-12825

Unauthorized Access to the Container Registry of other groups was disc ...

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-12825

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-15594

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-15594

GitLab 11.8 and later contains a security vulnerability that allows a ...

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-15592

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-15592

GitLab 12.2.2 and below contains a security vulnerability that allows ...

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-15592

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-15594

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад

Уязвимостей на страницу


Поделиться