Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.518.6202520262027

Недавние уязвимости Gitlab

Количество 5 237

ubuntu логотип

CVE-2018-14605

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the branch name during a Web IDE file commit.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2018-14604

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the tooltip of the job inside the CI/CD pipeline.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-14364

больше 7 лет назад

GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2018-14364

больше 7 лет назад

GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 1 ...

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2018-14364

больше 7 лет назад

GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2017-0921

больше 7 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2017-0921

больше 7 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10 ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2017-0919

больше 7 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-0919

больше 7 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-0919

больше 7 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2018-14605

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the branch name during a Web IDE file commit.

CVSS3: 5.4
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-14604

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the tooltip of the job inside the CI/CD pipeline.

CVSS3: 6.1
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-14364

GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component.

CVSS3: 9.8
39%
Средний
больше 7 лет назад
debian логотип
CVE-2018-14364

GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 1 ...

CVSS3: 9.8
39%
Средний
больше 7 лет назад
ubuntu логотип
CVE-2018-14364

GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component.

CVSS3: 9.8
39%
Средний
больше 7 лет назад
nvd логотип
CVE-2017-0921

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.

CVSS3: 8.1
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2017-0921

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10 ...

CVSS3: 8.1
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-0919

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

CVSS3: 7.5
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2017-0919

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10 ...

CVSS3: 7.5
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2017-0919

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

CVSS3: 7.5
0%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться