Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 920

ubuntu логотип

CVE-2019-16170

почти 7 лет назад

An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2019-7176

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2019-7176

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x ...

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2019-6791

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 3 of 3). When a project with visibility more permissive than the target group is imported, it will retain its prior visibility.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-6791

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-7176

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2019-6791

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 3 of 3). When a project with visibility more permissive than the target group is imported, it will retain its prior visibility.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-6997

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge request titles.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-6997

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-6996

почти 7 лет назад

An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers to view membership of private groups.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2019-16170

An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control.

CVSS3: 7.1
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-7176

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

CVSS3: 3.7
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-7176

An issue was discovered in GitLab Community and Enterprise Edition 8.x ...

CVSS3: 3.7
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-6791

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 3 of 3). When a project with visibility more permissive than the target group is imported, it will retain its prior visibility.

CVSS3: 6.5
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-6791

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.5
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-7176

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

CVSS3: 3.7
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-6791

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 3 of 3). When a project with visibility more permissive than the target group is imported, it will retain its prior visibility.

CVSS3: 6.5
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-6997

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge request titles.

CVSS3: 4.3
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-6997

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 4.3
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-6996

An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers to view membership of private groups.

CVSS3: 4.3
1%
Низкий
почти 7 лет назад

Уязвимостей на страницу


Поделиться