Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 920

github логотип

GHSA-23hx-3f44-x72r

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have, under certain circumstances, allowed an authenticated user with certain access to cause Denial of Service by creating specially crafted CI triggers via the API.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-845x-h4jv-2v89

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause Denial of Service by sending specially crafted requests to the Jira events endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35pf-5r93-c5jc

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause regular expression denial of service by sending specially crafted input to a merge request endpoint under certain conditions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-g3hq-7735-4x6v

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthorized user with Developer-role permissions to set pipeline variables for manually triggered jobs under certain conditions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-2845

5 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an authenticated user to cause denial of service by exploiting a Bitbucket Server import endpoint via repeatedly sending large responses.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-2845

5 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-1747

5 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-role users with insufficient privileges to make unauthorized modifications to protected Conan packages.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2026-1747

5 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-1725

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting versions from 18.9 before 18.9.1 that could have under certain conditions, allowed an unauthenticated user to cause denial of service by sending specially crafted requests to a CI jobs API endpoint.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-1725

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting versions from ...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-23hx-3f44-x72r

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have, under certain circumstances, allowed an authenticated user with certain access to cause Denial of Service by creating specially crafted CI triggers via the API.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-845x-h4jv-2v89

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause Denial of Service by sending specially crafted requests to the Jira events endpoint.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-35pf-5r93-c5jc

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause regular expression denial of service by sending specially crafted input to a merge request endpoint under certain conditions.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-g3hq-7735-4x6v

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthorized user with Developer-role permissions to set pipeline variables for manually triggered jobs under certain conditions.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-2845

An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an authenticated user to cause denial of service by exploiting a Bitbucket Server import endpoint via repeatedly sending large responses.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-2845

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-1747

GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-role users with insufficient privileges to make unauthorized modifications to protected Conan packages.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-1747

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 4.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-1725

GitLab has remediated an issue in GitLab CE/EE affecting versions from 18.9 before 18.9.1 that could have under certain conditions, allowed an unauthenticated user to cause denial of service by sending specially crafted requests to a CI jobs API endpoint.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-1725

GitLab has remediated an issue in GitLab CE/EE affecting versions from ...

CVSS3: 5.3
0%
Низкий
5 месяцев назад

Уязвимостей на страницу


Поделиться