Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.518.618.7202520262027

Недавние уязвимости Gitlab

Количество 5 237

debian логотип

CVE-2019-11605

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-11549

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-11549

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-11548

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2019-11548

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-11547

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-11547

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-11546

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-11546

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-11545

больше 6 лет назад

An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2019-11605

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11549

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11549

An issue was discovered in GitLab Community and Enterprise Edition 9.x ...

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11548

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11548

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11547

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues.

CVSS3: 6.1
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11547

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.1
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11546

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge.

CVSS3: 5.3
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11546

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.3
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11545

An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться