Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.618.718.8202520262027

Недавние уязвимости Gitlab

Количество 5 336

debian логотип

CVE-2025-0605

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2024-12093

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2024-12093

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2024-12093

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2025-0605

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

CVSS3: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2025-0679

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-0993

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-4979

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2025-4979

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2025-3111

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2025-0605

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 4.6
0%
Низкий
9 месяцев назад
nvd логотип
CVE-2024-12093

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

CVSS3: 6.8
0%
Низкий
9 месяцев назад
debian логотип
CVE-2024-12093

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.8
0%
Низкий
9 месяцев назад
ubuntu логотип
CVE-2024-12093

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

CVSS3: 6.8
0%
Низкий
9 месяцев назад
ubuntu логотип
CVE-2025-0605

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

CVSS3: 4.6
0%
Низкий
9 месяцев назад
ubuntu логотип
CVE-2025-0679

An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
ubuntu логотип
CVE-2025-0993

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
debian логотип
CVE-2025-4979

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 4.9
0%
Низкий
9 месяцев назад
nvd логотип
CVE-2025-4979

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.

CVSS3: 4.9
0%
Низкий
9 месяцев назад
debian логотип
CVE-2025-3111

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
9 месяцев назад

Уязвимостей на страницу


Поделиться