Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Количество 5 336
CVE-2025-0555
A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all ...
GHSA-wpxf-3mm2-76f8
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.
GHSA-g5qp-3jx2-p69r
An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could inject HMTL into the child item search potentially leading to XSS in certain situations.
CVE-2025-0475
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.
CVE-2025-0475
An issue has been discovered in GitLab CE/EE affecting all versions fr ...
CVE-2024-10925
A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to read Security policy YAML
CVE-2024-10925
A vulnerability in GitLab-EE affecting all versions from 16.2 prior to ...
CVE-2024-8186
An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could inject HMTL into the child item search potentially leading to XSS in certain situations.
CVE-2024-8186
An issue has been discovered in GitLab CE/EE affecting all versions fr ...
BDU:2025-02583
Уязвимость программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2025-0555 A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all ... | CVSS3: 7.7 | 0% Низкий | 11 месяцев назад | |
GHSA-wpxf-3mm2-76f8 An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances. | CVSS3: 8.7 | 0% Низкий | 12 месяцев назад | |
GHSA-g5qp-3jx2-p69r An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could inject HMTL into the child item search potentially leading to XSS in certain situations. | CVSS3: 5.4 | 0% Низкий | 12 месяцев назад | |
CVE-2025-0475 An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances. | CVSS3: 8.7 | 0% Низкий | 12 месяцев назад | |
CVE-2025-0475 An issue has been discovered in GitLab CE/EE affecting all versions fr ... | CVSS3: 8.7 | 0% Низкий | 12 месяцев назад | |
CVE-2024-10925 A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to read Security policy YAML | CVSS3: 5.3 | 0% Низкий | 12 месяцев назад | |
CVE-2024-10925 A vulnerability in GitLab-EE affecting all versions from 16.2 prior to ... | CVSS3: 5.3 | 0% Низкий | 12 месяцев назад | |
CVE-2024-8186 An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could inject HMTL into the child item search potentially leading to XSS in certain situations. | CVSS3: 5.4 | 0% Низкий | 12 месяцев назад | |
CVE-2024-8186 An issue has been discovered in GitLab CE/EE affecting all versions fr ... | CVSS3: 5.4 | 0% Низкий | 12 месяцев назад | |
BDU:2025-02583 Уязвимость программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS) | CVSS3: 5.4 | 0% Низкий | 12 месяцев назад |
Уязвимостей на страницу