Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 918

ubuntu логотип

CVE-2017-0919

около 8 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-0921

около 8 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2018-10379

около 8 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-10379

около 8 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterpris ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-10379

около 8 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-8801

больше 8 лет назад

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-8801

больше 8 лет назад

GitLab Community and Enterprise Editions version 8.3 up to 10.x before ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2018-8801

больше 8 лет назад

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-9244

больше 8 лет назад

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-9244

больше 8 лет назад

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vu ...

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2017-0919

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

CVSS3: 7.5
1%
Низкий
около 8 лет назад
ubuntu логотип
CVE-2017-0921

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.

CVSS3: 8.1
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-10379

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability.

CVSS3: 6.1
1%
Низкий
около 8 лет назад
debian логотип
CVE-2018-10379

An issue was discovered in GitLab Community Edition (CE) and Enterpris ...

CVSS3: 6.1
1%
Низкий
около 8 лет назад
ubuntu логотип
CVE-2018-10379

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability.

CVSS3: 6.1
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-8801

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
1%
Низкий
больше 8 лет назад
debian логотип
CVE-2018-8801

GitLab Community and Enterprise Editions version 8.3 up to 10.x before ...

CVSS3: 6.5
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2018-8801

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS3: 6.5
1%
Низкий
больше 8 лет назад
nvd логотип
CVE-2018-9244

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
debian логотип
CVE-2018-9244

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vu ...

CVSS3: 6.1
1%
Низкий
больше 8 лет назад

Уязвимостей на страницу


Поделиться