Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.518.618.7202520262027

Недавние уязвимости Gitlab

Количество 5 203

ubuntu логотип

CVE-2019-6788

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 3 of 6). For installations using GitHub or Bitbucket OAuth integrations, it is possible to use a covert redirect to obtain the user OAuth token for those services.

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2019-6995

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-6792

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error message will display instance internal information.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2019-6786

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-6783

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. GitLab Pages contains a directory traversal vulnerability that could lead to remote command execution.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-11605

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A small number of GitLab API endpoints would disclose project information when using a read_user scoped token.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-11605

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-11549

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-11549

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-11548

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2019-6788

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 3 of 6). For installations using GitHub or Bitbucket OAuth integrations, it is possible to use a covert redirect to obtain the user OAuth token for those services.

CVSS3: 7.5
20%
Средний
больше 6 лет назад
ubuntu логотип
CVE-2019-6995

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-6792

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error message will display instance internal information.

CVSS3: 5.3
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-6786

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known.

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-6783

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. GitLab Pages contains a directory traversal vulnerability that could lead to remote command execution.

CVSS3: 8.8
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11605

An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A small number of GitLab API endpoints would disclose project information when using a read_user scoped token.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11605

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11549

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11549

An issue was discovered in GitLab Community and Enterprise Edition 9.x ...

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11548

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.

CVSS3: 5.4
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться