Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 920

nvd логотип

CVE-2025-5846

около 1 года назад

An issue has been discovered in GitLab EE affecting all versions from 16.10 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to assign unrelated compliance frameworks to projects by sending crafted GraphQL mutations that bypassed framework-specific permission checks.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2025-5846

около 1 года назад

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2025-5315

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users with Guest role permissions to add child items to incident work items by sending crafted API requests that bypassed UI-enforced role restrictions.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-5315

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-3279

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-3279

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-2938

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval process resulted in unintended permission grants.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2025-2938

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2025-1754

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API requests, potentially leading to resource abuse and unauthorized content storage.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-1754

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2025-5846

An issue has been discovered in GitLab EE affecting all versions from 16.10 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to assign unrelated compliance frameworks to projects by sending crafted GraphQL mutations that bypassed framework-specific permission checks.

CVSS3: 2.7
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-5846

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 2.7
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-5315

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users with Guest role permissions to add child items to incident work items by sending crafted API requests that bypassed UI-enforced role restrictions.

CVSS3: 4.3
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-5315

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 4.3
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-3279

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests.

CVSS3: 6.5
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-3279

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-2938

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval process resulted in unintended permission grants.

CVSS3: 3.1
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-2938

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 3.1
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-1754

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API requests, potentially leading to resource abuse and unauthorized content storage.

CVSS3: 5.3
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-1754

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.3
0%
Низкий
около 1 года назад

Уязвимостей на страницу


Поделиться