Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.518.618.7202520262027

Недавние уязвимости Gitlab

Количество 5 237

ubuntu логотип

CVE-2019-5463

больше 6 лет назад

An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2019-5473

больше 6 лет назад

An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2019-5461

больше 6 лет назад

An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2019-5461

больше 6 лет назад

An input validation problem was discovered in the GitHub service integ ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2019-5461

больше 6 лет назад

An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2019-14943

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-14943

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12. ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2019-14943

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2022-02144

больше 6 лет назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с неправильной авторизацией, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2018-19584

больше 6 лет назад

GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2019-5463

An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.3
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-5473

An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.

CVSS3: 7.2
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-5461

An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 3.5
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-5461

An input validation problem was discovered in the GitHub service integ ...

CVSS3: 3.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-5461

An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 3.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-14943

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS3: 9.8
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-14943

An issue was discovered in GitLab Community and Enterprise Edition 12. ...

CVSS3: 9.8
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-14943

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS3: 9.8
0%
Низкий
больше 6 лет назад
fstec логотип
BDU:2022-02144

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с неправильной авторизацией, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-19584

GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться