Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 920

nvd логотип

CVE-2019-12430

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-12430

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-12429

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-12429

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-12428

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-12428

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 6.8 ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2019-12428

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2019-12431

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-12430

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-12429

больше 6 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2019-12430

An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection.

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12430

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-12429

An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12429

An issue was discovered in GitLab Community and Enterprise Edition 11. ...

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-12428

An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12428

An issue was discovered in GitLab Community and Enterprise Edition 6.8 ...

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-12428

An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-12431

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control.

CVSS3: 4.3
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-12430

An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection.

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-12429

An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.

CVSS3: 6.5
1%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться