Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 918

debian логотип

CVE-2019-5883

около 7 лет назад

An Incorrect Access Control issue was discovered in GitLab Community a ...

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2018-20500

около 7 лет назад

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-20500

около 7 лет назад

An insecure permissions issue was discovered in GitLab Community and E ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-19585

около 7 лет назад

GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2018-19585

около 7 лет назад

GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11 ...

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2018-19585

около 7 лет назад

GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2018-20500

около 7 лет назад

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-6797

около 7 лет назад

An information disclosure issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitHub token used in CI/CD for External Repos was being leaked to project maintainers in the UI.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-6781

около 7 лет назад

An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-6787

около 7 лет назад

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitLab API allowed project Maintainers and Owners to view the trigger tokens of other project users.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2019-5883

An Incorrect Access Control issue was discovered in GitLab Community a ...

CVSS3: 9.1
2%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-20500

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

CVSS3: 7.5
1%
Низкий
около 7 лет назад
debian логотип
CVE-2018-20500

An insecure permissions issue was discovered in GitLab Community and E ...

CVSS3: 7.5
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-19585

GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.

CVSS3: 7.5
15%
Средний
около 7 лет назад
debian логотип
CVE-2018-19585

GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11 ...

CVSS3: 7.5
15%
Средний
около 7 лет назад
ubuntu логотип
CVE-2018-19585

GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.

CVSS3: 7.5
15%
Средний
около 7 лет назад
ubuntu логотип
CVE-2018-20500

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

CVSS3: 7.5
1%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2019-6797

An information disclosure issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitHub token used in CI/CD for External Repos was being leaked to project maintainers in the UI.

CVSS3: 7.5
2%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2019-6781

An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.

CVSS3: 7.5
1%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2019-6787

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitLab API allowed project Maintainers and Owners to view the trigger tokens of other project users.

CVSS3: 6.5
1%
Низкий
около 7 лет назад

Уязвимостей на страницу


Поделиться