Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 918

fstec логотип

BDU:2026-09093

около 1 месяца назад

Уязвимость программного интерфейса подсистемы CI/CD программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.4
EPSS: Низкий
fstec логотип

BDU:2026-09078

около 1 месяца назад

Уязвимость реестра пакетов Maven программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, позволяющая нарушителю обойти существующие механизмы безопасности

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2026-09076

около 1 месяца назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, связанная с недостатками процедуры авторизации, позволяющая нарушителю повысить свои привилегии

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-c4m8-pv9j-v7mm

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to read arbitrary files from the Gitaly server and access internal network resources during repository import, due to insufficient validation of secondary URLs.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-hm74-p2xf-rqgc

около 2 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with Security Manager-role permissions to manage project security configuration even when the relevant feature was in a disabled state, due to incorrect authorization enforcement.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7mq5-3vcf-v96v

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to hide changes from merge request diff views due to improper input handling of file names.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-q9j8-24p8-jq8j

около 2 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to add unauthorized email addresses to a targeted user's account due to improper sanitization of user-supplied input in certain group setting fields.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-cx4g-hr74-m89m

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsing middleware.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-c3j7-m5hr-8w75

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to modify hidden merge requests due to incorrect authorization enforcements.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-r82j-g6q9-mvx8

около 2 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with group Owner role to take over another group member's GitLab account due to improper authorization in the Group SAML identity management functionality.

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
fstec логотип
BDU:2026-09093

Уязвимость программного интерфейса подсистемы CI/CD программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.4
0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2026-09078

Уязвимость реестра пакетов Maven программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, позволяющая нарушителю обойти существующие механизмы безопасности

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2026-09076

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, связанная с недостатками процедуры авторизации, позволяющая нарушителю повысить свои привилегии

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-c4m8-pv9j-v7mm

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to read arbitrary files from the Gitaly server and access internal network resources during repository import, due to insufficient validation of secondary URLs.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-hm74-p2xf-rqgc

GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with Security Manager-role permissions to manage project security configuration even when the relevant feature was in a disabled state, due to incorrect authorization enforcement.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-7mq5-3vcf-v96v

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to hide changes from merge request diff views due to improper input handling of file names.

CVSS3: 3.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-q9j8-24p8-jq8j

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to add unauthorized email addresses to a targeted user's account due to improper sanitization of user-supplied input in certain group setting fields.

CVSS3: 7.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-cx4g-hr74-m89m

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsing middleware.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-c3j7-m5hr-8w75

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to modify hidden merge requests due to incorrect authorization enforcements.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-r82j-g6q9-mvx8

GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with group Owner role to take over another group member's GitLab account due to improper authorization in the Group SAML identity management functionality.

CVSS3: 8.7
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу


Поделиться