Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.618.718.8202520262027

Недавние уязвимости Gitlab

Количество 5 336

ubuntu логотип

CVE-2018-16050

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-16051

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Orphaned Upload Files Exposure.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2018-16049

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2018-16048

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Missing Authorization Control for API Repository Storage.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-12607

больше 7 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XSS issue due to a lack of output encoding.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-12607

больше 7 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edi ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-12606

больше 7 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-12606

больше 7 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edi ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-12605

больше 7 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' contained a XSS issue due to it allowing arbitrary protocols as a parameter.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-12605

больше 7 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edi ...

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2018-16050

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View.

CVSS3: 6.1
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-16051

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Orphaned Upload Files Exposure.

CVSS3: 6.5
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-16049

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.

CVSS3: 9.8
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-16048

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Missing Authorization Control for API Repository Storage.

CVSS3: 6.5
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12607

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XSS issue due to a lack of output encoding.

CVSS3: 5.4
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12607

An issue was discovered in GitLab Community Edition and Enterprise Edi ...

CVSS3: 5.4
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12606

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature.

CVSS3: 5.4
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12606

An issue was discovered in GitLab Community Edition and Enterprise Edi ...

CVSS3: 5.4
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12605

An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' contained a XSS issue due to it allowing arbitrary protocols as a parameter.

CVSS3: 5.4
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12605

An issue was discovered in GitLab Community Edition and Enterprise Edi ...

CVSS3: 5.4
0%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться