Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.518.618.7202520262027

Недавние уязвимости Gitlab

Количество 5 237

debian логотип

CVE-2018-19573

больше 6 лет назад

GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11. ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-19572

больше 6 лет назад

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2018-19572

больше 6 лет назад

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-c ...

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2018-19570

больше 6 лет назад

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-19570

больше 6 лет назад

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11 ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-19569

больше 6 лет назад

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-19569

больше 6 лет назад

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4 ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2018-19575

больше 6 лет назад

GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2018-19572

больше 6 лет назад

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2018-19574

больше 6 лет назад

GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in the OAuth authorization page.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2018-19573

GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11. ...

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-19572

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

CVSS3: 5.9
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-19572

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-c ...

CVSS3: 5.9
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-19570

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-19570

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11 ...

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-19569

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-19569

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4 ...

CVSS3: 8.8
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-19575

GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-19572

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

CVSS3: 5.9
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-19574

GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in the OAuth authorization page.

CVSS3: 5.4
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться