Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.518.618.7202520262027

Недавние уязвимости Gitlab

Количество 5 267

nvd логотип

CVE-2019-19314

почти 6 лет назад

GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-19314

почти 6 лет назад

GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens i ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-19313

почти 6 лет назад

GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-19313

почти 6 лет назад

GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Servi ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-19312

почти 6 лет назад

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2019-19312

почти 6 лет назад

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access C ...

CVSS3: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2019-19312

почти 6 лет назад

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

CVSS3: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2019-19629

почти 6 лет назад

In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-19313

почти 6 лет назад

GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-19628

почти 6 лет назад

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2019-19314

GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-19314

GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens i ...

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-19313

GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-19313

GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Servi ...

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-19312

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

CVSS3: 5.8
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-19312

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access C ...

CVSS3: 5.8
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-19312

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

CVSS3: 5.8
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-19629

In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-19313

GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-19628

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

CVSS3: 9.8
2%
Низкий
почти 6 лет назад

Уязвимостей на страницу


Поделиться