Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.618.718.8202520262027

Недавние уязвимости Gitlab

Количество 5 336

ubuntu логотип

CVE-2019-5467

больше 6 лет назад

An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result in a persistent XSS. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-5461

больше 6 лет назад

An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2019-5461

больше 6 лет назад

An input validation problem was discovered in the GitHub service integ ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2019-5461

больше 6 лет назад

An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2019-14943

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-14943

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12. ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2019-14943

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2022-02144

больше 6 лет назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с неправильной авторизацией, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2018-19584

больше 6 лет назад

GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-19584

больше 6 лет назад

GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2019-5467

An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result in a persistent XSS. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-5461

An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 3.5
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-5461

An input validation problem was discovered in the GitHub service integ ...

CVSS3: 3.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-5461

An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 3.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-14943

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS3: 9.8
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-14943

An issue was discovered in GitLab Community and Enterprise Edition 12. ...

CVSS3: 9.8
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-14943

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS3: 9.8
0%
Низкий
больше 6 лет назад
fstec логотип
BDU:2022-02144

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с неправильной авторизацией, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-19584

GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-19584

GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 ...

CVSS3: 7.5
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться