Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 920
CVE-2019-12434
An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure.
CVE-2019-12432
An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure.
CVE-2019-12433
An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settings allow creating internal projects in private groups, leading to multiple permission issues.
CVE-2020-8113
GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.
CVE-2020-8113
GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.
CVE-2020-8113
GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.
CVE-2020-8795
In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.
CVE-2020-8795
In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a gro ...
CVE-2020-8795
In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.
CVE-2019-12825
Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2019-12434 An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12432 An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12433 An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settings allow creating internal projects in private groups, leading to multiple permission issues. | CVSS3: 5.3 | 1% Низкий | больше 6 лет назад | |
CVE-2020-8113 GitLab 10.7 and later through 12.7.2 has Incorrect Access Control. | CVSS3: 9.8 | 1% Низкий | больше 6 лет назад | |
CVE-2020-8113 GitLab 10.7 and later through 12.7.2 has Incorrect Access Control. | CVSS3: 9.8 | 1% Низкий | больше 6 лет назад | |
CVE-2020-8113 GitLab 10.7 and later through 12.7.2 has Incorrect Access Control. | CVSS3: 9.8 | 1% Низкий | больше 6 лет назад | |
CVE-2020-8795 In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users. | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад | |
CVE-2020-8795 In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a gro ... | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад | |
CVE-2020-8795 In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users. | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12825 Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад |
Уязвимостей на страницу