Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Количество 5 331
CVE-2017-0920
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.
CVE-2017-0920
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10 ...
CVE-2017-0920
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.
CVE-2018-3710
Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.
CVE-2018-3710
Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable ...
CVE-2017-0927
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.
CVE-2017-0927
Gitlab Community Edition version 10.3 is vulnerable to an improper aut ...
CVE-2017-0926
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login.
CVE-2017-0926
Gitlab Community Edition version 10.3 is vulnerable to an improper aut ...
CVE-2017-0925
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2017-0920 GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance. | CVSS3: 4.3 | 0% Низкий | почти 8 лет назад | |
CVE-2017-0920 GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10 ... | CVSS3: 4.3 | 0% Низкий | почти 8 лет назад | |
CVE-2017-0920 GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance. | CVSS3: 4.3 | 0% Низкий | почти 8 лет назад | |
CVE-2018-3710 Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution. | CVSS3: 7.8 | 5% Низкий | почти 8 лет назад | |
CVE-2018-3710 Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable ... | CVSS3: 7.8 | 5% Низкий | почти 8 лет назад | |
CVE-2017-0927 Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users. | CVSS3: 6.5 | 0% Низкий | почти 8 лет назад | |
CVE-2017-0927 Gitlab Community Edition version 10.3 is vulnerable to an improper aut ... | CVSS3: 6.5 | 0% Низкий | почти 8 лет назад | |
CVE-2017-0926 Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login. | CVSS3: 8.8 | 0% Низкий | почти 8 лет назад | |
CVE-2017-0926 Gitlab Community Edition version 10.3 is vulnerable to an improper aut ... | CVSS3: 8.8 | 0% Низкий | почти 8 лет назад | |
CVE-2017-0925 Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password. | CVSS3: 7.2 | 0% Низкий | почти 8 лет назад |
Уязвимостей на страницу