Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.618.718.8202520262027

Недавние уязвимости Gitlab

Количество 5 332

debian логотип

CVE-2019-11000

больше 6 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 1 ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-11000

больше 6 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-19359

почти 7 лет назад

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-19359

почти 7 лет назад

GitLab Community and Enterprise Edition 8.9 and later and before 11.5. ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-18643

почти 7 лет назад

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-18643

почти 7 лет назад

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3 ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-19359

почти 7 лет назад

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2018-18643

почти 7 лет назад

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-10301

почти 7 лет назад

A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-10300

почти 7 лет назад

A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2019-11000

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 1 ...

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-11000

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-19359

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

CVSS3: 8.8
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2018-19359

GitLab Community and Enterprise Edition 8.9 and later and before 11.5. ...

CVSS3: 8.8
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2018-18643

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

CVSS3: 6.1
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2018-18643

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3 ...

CVSS3: 6.1
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2018-19359

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

CVSS3: 8.8
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2018-18643

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

CVSS3: 6.1
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-10301

A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS3: 8.8
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-10300

A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS3: 8
0%
Низкий
почти 7 лет назад

Уязвимостей на страницу


Поделиться