Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 920

ubuntu логотип

CVE-2019-13005

больше 6 лет назад

An issue was discovered in GitLab Enterprise Edition and Community Edition 1.10 through 12.0.2. The GitLab graphql service was vulnerable to multiple authorization issues that disclosed restricted user, group, and repository metadata to unauthorized users. It has Incorrect Access Control.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-12445

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-12434

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-12434

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-12433

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settings allow creating internal projects in private groups, leading to multiple permission issues.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-12433

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-12432

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-12432

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.1 ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-12431

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-12431

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.1 ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2019-13005

An issue was discovered in GitLab Enterprise Edition and Community Edition 1.10 through 12.0.2. The GitLab graphql service was vulnerable to multiple authorization issues that disclosed restricted user, group, and repository metadata to unauthorized users. It has Incorrect Access Control.

CVSS3: 4.3
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-12445

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.

CVSS3: 5.4
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-12434

An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure.

CVSS3: 4.3
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12434

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 4.3
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-12433

An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settings allow creating internal projects in private groups, leading to multiple permission issues.

CVSS3: 5.3
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12433

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 5.3
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-12432

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure.

CVSS3: 4.3
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12432

An issue was discovered in GitLab Community and Enterprise Edition 8.1 ...

CVSS3: 4.3
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-12431

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control.

CVSS3: 4.3
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12431

An issue was discovered in GitLab Community and Enterprise Edition 8.1 ...

CVSS3: 4.3
1%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться