Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"
Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

18.618.718.8202520262027

Недавние уязвимости Gitlab

Количество 5 336

nvd логотип

CVE-2024-8179

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-8179

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2024-12570

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2024-12570

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2024-12292

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.

CVSS3: 4
EPSS: Низкий
debian логотип

CVE-2024-12292

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4
EPSS: Низкий
nvd логотип

CVE-2024-11274

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2024-11274

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2024-10043

около 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2024-10043

около 1 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-8179

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.

CVSS3: 5.4
1%
Низкий
около 1 года назад
debian логотип
CVE-2024-8179

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.4
1%
Низкий
около 1 года назад
nvd логотип
CVE-2024-12570

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-12570

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.7
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-12292

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.

CVSS3: 4
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-12292

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-11274

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.

CVSS3: 8.7
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-11274

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 8.7
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-10043

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure.

CVSS3: 3.1
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-10043

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу


Поделиться