Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 920
CVE-2019-13005
An issue was discovered in GitLab Enterprise Edition and Community Edition 1.10 through 12.0.2. The GitLab graphql service was vulnerable to multiple authorization issues that disclosed restricted user, group, and repository metadata to unauthorized users. It has Incorrect Access Control.
CVE-2019-12445
An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.
CVE-2019-12434
An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure.
CVE-2019-12434
An issue was discovered in GitLab Community and Enterprise Edition 10. ...
CVE-2019-12433
An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settings allow creating internal projects in private groups, leading to multiple permission issues.
CVE-2019-12433
An issue was discovered in GitLab Community and Enterprise Edition 11. ...
CVE-2019-12432
An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure.
CVE-2019-12432
An issue was discovered in GitLab Community and Enterprise Edition 8.1 ...
CVE-2019-12431
An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control.
CVE-2019-12431
An issue was discovered in GitLab Community and Enterprise Edition 8.1 ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2019-13005 An issue was discovered in GitLab Enterprise Edition and Community Edition 1.10 through 12.0.2. The GitLab graphql service was vulnerable to multiple authorization issues that disclosed restricted user, group, and repository metadata to unauthorized users. It has Incorrect Access Control. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12445 An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS. | CVSS3: 5.4 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12434 An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12434 An issue was discovered in GitLab Community and Enterprise Edition 10. ... | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12433 An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settings allow creating internal projects in private groups, leading to multiple permission issues. | CVSS3: 5.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12433 An issue was discovered in GitLab Community and Enterprise Edition 11. ... | CVSS3: 5.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12432 An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12432 An issue was discovered in GitLab Community and Enterprise Edition 8.1 ... | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12431 An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12431 An issue was discovered in GitLab Community and Enterprise Edition 8.1 ... | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад |
Уязвимостей на страницу