Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.618.718.8202520262027

Недавние уязвимости Gitlab

Количество 5 336

nvd логотип

CVE-2025-2255

11 месяцев назад

An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2025-2255

11 месяцев назад

An issue has been discovered in Gitlab EE/CE for AppSec affecting all ...

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2025-2242

11 месяцев назад

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-2242

11 месяцев назад

An improper access control vulnerability in GitLab CE/EE affecting all ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-0811

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2025-0811

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2024-9773

11 месяцев назад

An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2024-9773

11 месяцев назад

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2025-0811

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2025-2255

11 месяцев назад

An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2025-2255

An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.

CVSS3: 8.7
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-2255

An issue has been discovered in Gitlab EE/CE for AppSec affecting all ...

CVSS3: 8.7
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-2242

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-2242

An improper access control vulnerability in GitLab CE/EE affecting all ...

CVSS3: 7.5
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-0811

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.

CVSS3: 8.7
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-0811

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2024-9773

An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI.

CVSS3: 3.7
0%
Низкий
11 месяцев назад
debian логотип
CVE-2024-9773

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 3.7
0%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2025-0811

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.

CVSS3: 8.7
0%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2025-2255

An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.

CVSS3: 8.7
0%
Низкий
11 месяцев назад

Уязвимостей на страницу


Поделиться