Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 920
CVE-2019-12825
Unauthorized Access to the Container Registry of other groups was disc ...
CVE-2019-12825
Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.
CVE-2019-15594
GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.
CVE-2019-15594
GitLab 11.8 and later contains a security vulnerability that allows a ...
CVE-2019-15592
GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.
CVE-2019-15592
GitLab 12.2.2 and below contains a security vulnerability that allows ...
CVE-2019-15594
GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.
CVE-2019-15592
GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.
CVE-2020-6833
An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.
CVE-2020-6833
An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhors ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2019-12825 Unauthorized Access to the Container Registry of other groups was disc ... | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12825 Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15594 GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15594 GitLab 11.8 and later contains a security vulnerability that allows a ... | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15592 GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15592 GitLab 12.2.2 and below contains a security vulnerability that allows ... | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15594 GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15592 GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2020-6833 An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling. | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад | |
CVE-2020-6833 An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhors ... | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад |
Уязвимостей на страницу