Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 920

nvd логотип

CVE-2020-10079

больше 6 лет назад

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-10079

больше 6 лет назад

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-10078

больше 6 лет назад

GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-10078

больше 6 лет назад

GitLab 12.1 through 12.8.1 allows XSS. The merge request submission fo ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-10083

больше 6 лет назад

GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2020-10090

больше 6 лет назад

GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-10086

больше 6 лет назад

GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-10092

больше 6 лет назад

GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-10080

больше 6 лет назад

GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-10087

больше 6 лет назад

GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2020-10079

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.

CVSS3: 5.3
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2020-10079

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain ...

CVSS3: 5.3
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2020-10078

GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2020-10078

GitLab 12.1 through 12.8.1 allows XSS. The merge request submission fo ...

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2020-10083

GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.

CVSS3: 9.1
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2020-10090

GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.

CVSS3: 5.3
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2020-10086

GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.

CVSS3: 5.3
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2020-10092

GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2020-10080

GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.

CVSS3: 5.3
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2020-10087

GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.

CVSS3: 7.5
1%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться