Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Количество 5 336
CVE-2025-2469
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users.
CVE-2025-2469
An issue has been discovered in GitLab CE/EE affecting all versions fr ...
CVE-2025-2408
An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.
CVE-2025-2408
An issue has been discovered in GitLab CE/EE affecting all versions fr ...
CVE-2025-1677
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A denial of service could occur upon injecting oversized payloads into CI pipeline exports.
CVE-2025-1677
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE af ...
CVE-2024-11129
An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted searches with sensitive keywords to get the count of issues containing the searched term."
CVE-2024-11129
An issue has been discovered in GitLab EE affecting all versions from ...
CVE-2025-1677
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A denial of service could occur upon injecting oversized payloads into CI pipeline exports.
CVE-2025-2408
An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2025-2469 An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users. | CVSS3: 3.7 | 0% Низкий | 10 месяцев назад | |
CVE-2025-2469 An issue has been discovered in GitLab CE/EE affecting all versions fr ... | CVSS3: 3.7 | 0% Низкий | 10 месяцев назад | |
CVE-2025-2408 An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information. | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад | |
CVE-2025-2408 An issue has been discovered in GitLab CE/EE affecting all versions fr ... | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад | |
CVE-2025-1677 A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A denial of service could occur upon injecting oversized payloads into CI pipeline exports. | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
CVE-2025-1677 A Denial of Service (DoS) issue has been discovered in GitLab CE/EE af ... | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
CVE-2024-11129 An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted searches with sensitive keywords to get the count of issues containing the searched term." | CVSS3: 6.3 | 0% Низкий | 10 месяцев назад | |
CVE-2024-11129 An issue has been discovered in GitLab EE affecting all versions from ... | CVSS3: 6.3 | 0% Низкий | 10 месяцев назад | |
CVE-2025-1677 A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A denial of service could occur upon injecting oversized payloads into CI pipeline exports. | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
CVE-2025-2408 An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information. | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад |
Уязвимостей на страницу