Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 920

debian логотип

CVE-2025-2256

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-1250

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed an authenticated user to stall background job processing by sending specially crafted commit messages, merge request descriptions, or notes.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-1250

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-10094

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrative operations by creating tokens with excessively large names.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-10094

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2025-12841

11 месяцев назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab CE/EE, связанная с недостаточной проверкой запросов на стороне сервера, позволяющая нарушителю осуществить SSRF-атаку

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2025-11451

11 месяцев назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, связанная с исчерпанием ресурсов памяти, позволяющая нарушителю вызвать перезагрузку устройства или отказ в обслуживании

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2025-11107

11 месяцев назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab CE/EE, связанная с недостатками механизма ограничения количества входных данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-rq6q-w27x-f9x2

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that that under certain conditions could have allowed an unauthenticated attacker to cause a denial-of-service condition affecting all users by sending specially crafted GraphQL requests.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-qccf-5wwv-jq8x

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.

CVSS3: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2025-2256

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 7.5
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-1250

An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed an authenticated user to stall background job processing by sending specially crafted commit messages, merge request descriptions, or notes.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-1250

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-10094

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrative operations by creating tokens with excessively large names.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-10094

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-12841

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab CE/EE, связанная с недостаточной проверкой запросов на стороне сервера, позволяющая нарушителю осуществить SSRF-атаку

CVSS3: 8.8
1%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-11451

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, связанная с исчерпанием ресурсов памяти, позволяющая нарушителю вызвать перезагрузку устройства или отказ в обслуживании

CVSS3: 6.5
0%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-11107

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab CE/EE, связанная с недостатками механизма ограничения количества входных данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-rq6q-w27x-f9x2

An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that that under certain conditions could have allowed an unauthenticated attacker to cause a denial-of-service condition affecting all users by sending specially crafted GraphQL requests.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-qccf-5wwv-jq8x

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.

CVSS3: 5.8
0%
Низкий
11 месяцев назад

Уязвимостей на страницу


Поделиться