Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.018.118.220252026

Недавние уязвимости Gitlab

Количество 4 706

ubuntu логотип

CVE-2018-16049

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2018-16051

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Orphaned Upload Files Exposure.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2018-16050

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-16048

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Missing Authorization Control for API Repository Storage.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-12607

около 7 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XSS issue due to a lack of output encoding.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-12607

около 7 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edi ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-12606

около 7 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-12606

около 7 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edi ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-12605

около 7 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' contained a XSS issue due to it allowing arbitrary protocols as a parameter.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-12605

около 7 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edi ...

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2018-16049

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.

CVSS3: 9.8
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2018-16051

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Orphaned Upload Files Exposure.

CVSS3: 6.5
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2018-16050

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View.

CVSS3: 6.1
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2018-16048

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Missing Authorization Control for API Repository Storage.

CVSS3: 6.5
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2018-12607

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XSS issue due to a lack of output encoding.

CVSS3: 5.4
0%
Низкий
около 7 лет назад
debian логотип
CVE-2018-12607

An issue was discovered in GitLab Community Edition and Enterprise Edi ...

CVSS3: 5.4
0%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-12606

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature.

CVSS3: 5.4
0%
Низкий
около 7 лет назад
debian логотип
CVE-2018-12606

An issue was discovered in GitLab Community Edition and Enterprise Edi ...

CVSS3: 5.4
0%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-12605

An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' contained a XSS issue due to it allowing arbitrary protocols as a parameter.

CVSS3: 5.4
0%
Низкий
около 7 лет назад
debian логотип
CVE-2018-12605

An issue was discovered in GitLab Community Edition and Enterprise Edi ...

CVSS3: 5.4
0%
Низкий
около 7 лет назад

Уязвимостей на страницу


Поделиться