Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 920

debian логотип

CVE-2019-6793

почти 7 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11 ...

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2019-6792

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error message will display instance internal information.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-6792

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-6789

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 4 of 6). In some cases, users without project permissions will receive emails after a project move. For private projects, this will disclose the new project namespace to an unauthorized user.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-6789

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-6788

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 3 of 6). For installations using GitHub or Bitbucket OAuth integrations, it is possible to use a covert redirect to obtain the user OAuth token for those services.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-6788

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-6786

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-6786

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-6785

почти 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Denial of Service. Inputting an overly long string into a Markdown field could cause a denial of service.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2019-6793

An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11 ...

CVSS3: 7
4%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-6792

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error message will display instance internal information.

CVSS3: 5.3
2%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-6792

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 5.3
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-6789

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 4 of 6). In some cases, users without project permissions will receive emails after a project move. For private projects, this will disclose the new project namespace to an unauthorized user.

CVSS3: 4.3
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-6789

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 4.3
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-6788

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 3 of 6). For installations using GitHub or Bitbucket OAuth integrations, it is possible to use a covert redirect to obtain the user OAuth token for those services.

CVSS3: 7.5
4%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-6788

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 7.5
4%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-6786

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known.

CVSS3: 6.5
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-6786

An issue was discovered in GitLab Community and Enterprise Edition bef ...

CVSS3: 6.5
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-6785

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Denial of Service. Inputting an overly long string into a Markdown field could cause a denial of service.

CVSS3: 6.5
1%
Низкий
почти 7 лет назад

Уязвимостей на страницу


Поделиться