Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.618.718.8202520262027

Недавние уязвимости Gitlab

Количество 5 336

debian логотип

CVE-2019-6797

больше 6 лет назад

An information disclosure issue was discovered in GitLab Enterprise Ed ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-6790

больше 6 лет назад

An Incorrect Access Control (issue 2 of 3) issue was discovered in GitLab Community and Enterprise Edition 8.14 and later but before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. Guest users were able to view the list of a group's merge requests.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-6790

больше 6 лет назад

An Incorrect Access Control (issue 2 of 3) issue was discovered in Git ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-6787

больше 6 лет назад

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitLab API allowed project Maintainers and Owners to view the trigger tokens of other project users.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-6787

больше 6 лет назад

An Incorrect Access Control issue was discovered in GitLab Community a ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-6781

больше 6 лет назад

An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-6781

больше 6 лет назад

An Improper Input Validation issue was discovered in GitLab Community ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-5883

больше 6 лет назад

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2019-5883

больше 6 лет назад

An Incorrect Access Control issue was discovered in GitLab Community a ...

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2018-20500

больше 6 лет назад

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2019-6797

An information disclosure issue was discovered in GitLab Enterprise Ed ...

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-6790

An Incorrect Access Control (issue 2 of 3) issue was discovered in GitLab Community and Enterprise Edition 8.14 and later but before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. Guest users were able to view the list of a group's merge requests.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-6790

An Incorrect Access Control (issue 2 of 3) issue was discovered in Git ...

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-6787

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitLab API allowed project Maintainers and Owners to view the trigger tokens of other project users.

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-6787

An Incorrect Access Control issue was discovered in GitLab Community a ...

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-6781

An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-6781

An Improper Input Validation issue was discovered in GitLab Community ...

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-5883

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

CVSS3: 9.1
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-5883

An Incorrect Access Control issue was discovered in GitLab Community a ...

CVSS3: 9.1
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-20500

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться