Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 920
CVE-2025-2256
An issue has been discovered in GitLab CE/EE affecting all versions fr ...
CVE-2025-1250
An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed an authenticated user to stall background job processing by sending specially crafted commit messages, merge request descriptions, or notes.
CVE-2025-1250
An issue has been discovered in GitLab CE/EE affecting all versions fr ...
CVE-2025-10094
An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrative operations by creating tokens with excessively large names.
CVE-2025-10094
An issue has been discovered in GitLab CE/EE affecting all versions fr ...
BDU:2025-12841
Уязвимость программной платформы на базе git для совместной работы над кодом GitLab CE/EE, связанная с недостаточной проверкой запросов на стороне сервера, позволяющая нарушителю осуществить SSRF-атаку
BDU:2025-11451
Уязвимость программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, связанная с исчерпанием ресурсов памяти, позволяющая нарушителю вызвать перезагрузку устройства или отказ в обслуживании
BDU:2025-11107
Уязвимость программной платформы на базе git для совместной работы над кодом GitLab CE/EE, связанная с недостатками механизма ограничения количества входных данных, позволяющая нарушителю вызвать отказ в обслуживании
GHSA-rq6q-w27x-f9x2
An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that that under certain conditions could have allowed an unauthenticated attacker to cause a denial-of-service condition affecting all users by sending specially crafted GraphQL requests.
GHSA-qccf-5wwv-jq8x
An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2025-2256 An issue has been discovered in GitLab CE/EE affecting all versions fr ... | CVSS3: 7.5 | 0% Низкий | 11 месяцев назад | |
CVE-2025-1250 An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed an authenticated user to stall background job processing by sending specially crafted commit messages, merge request descriptions, or notes. | CVSS3: 6.5 | 0% Низкий | 11 месяцев назад | |
CVE-2025-1250 An issue has been discovered in GitLab CE/EE affecting all versions fr ... | CVSS3: 6.5 | 0% Низкий | 11 месяцев назад | |
CVE-2025-10094 An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrative operations by creating tokens with excessively large names. | CVSS3: 6.5 | 0% Низкий | 11 месяцев назад | |
CVE-2025-10094 An issue has been discovered in GitLab CE/EE affecting all versions fr ... | CVSS3: 6.5 | 0% Низкий | 11 месяцев назад | |
BDU:2025-12841 Уязвимость программной платформы на базе git для совместной работы над кодом GitLab CE/EE, связанная с недостаточной проверкой запросов на стороне сервера, позволяющая нарушителю осуществить SSRF-атаку | CVSS3: 8.8 | 1% Низкий | 11 месяцев назад | |
BDU:2025-11451 Уязвимость программной платформы на базе git для совместной работы над кодом GitLab EE/ CE, связанная с исчерпанием ресурсов памяти, позволяющая нарушителю вызвать перезагрузку устройства или отказ в обслуживании | CVSS3: 6.5 | 0% Низкий | 11 месяцев назад | |
BDU:2025-11107 Уязвимость программной платформы на базе git для совместной работы над кодом GitLab CE/EE, связанная с недостатками механизма ограничения количества входных данных, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | 11 месяцев назад | |
GHSA-rq6q-w27x-f9x2 An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that that under certain conditions could have allowed an unauthenticated attacker to cause a denial-of-service condition affecting all users by sending specially crafted GraphQL requests. | CVSS3: 5.3 | 0% Низкий | 11 месяцев назад | |
GHSA-qccf-5wwv-jq8x An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API. | CVSS3: 5.8 | 0% Низкий | 11 месяцев назад |
Уязвимостей на страницу