Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 918

nvd логотип

CVE-2018-18643

больше 7 лет назад

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-18643

больше 7 лет назад

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3 ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-18643

больше 7 лет назад

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-19359

больше 7 лет назад

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-10301

больше 7 лет назад

A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-10300

больше 7 лет назад

A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2019-9890

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2019-9890

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2019-9756

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control, a different vulnerability than CVE-2019-9732.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-9756

больше 7 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2018-18643

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

CVSS3: 6.1
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-18643

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3 ...

CVSS3: 6.1
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-18643

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

CVSS3: 6.1
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-19359

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

CVSS3: 8.8
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2019-10301

A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2019-10300

A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS3: 8
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2019-9890

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

CVSS3: 9.1
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2019-9890

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 9.1
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2019-9756

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control, a different vulnerability than CVE-2019-9732.

CVSS3: 9.8
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2019-9756

An issue was discovered in GitLab Community and Enterprise Edition 10. ...

CVSS3: 9.8
2%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться