Записи gitlab
1 481 опубликованных записей вендора gitlab.
Профиль для исследователя
- Попали в KEV
- 5 · 0,3 %
- С эксплойтом
- 11 · 0,7 %
- Pre-auth RCE
- 26
- С записью об исправлении
- 42 %
- Медиана: публикация → KEV
- 194 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')180
- CWE-863 Incorrect Authorization129
- CWE-770 Allocation of Resources Without Limits or Throttling93
- CWE-862 Missing Authorization81
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor63
- CWE-400 Uncontrolled Resource Consumption48
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
1 481 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2021-22205Готовый эксплойт | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.gitlab · gitlab · CWE-94 | Критическая10,0 | KEV | 99,7 % | 23 апр. 2021 г. |
97Срочно | CVE-2023-7028Готовый эксплойт | Weak Password Recovery Mechanism for Forgotten Password in GitLabgitlab · gitlab · CWE-640 | Критическая9,8 | KEV | 94,6 % | 12 янв. 2024 г. |
97Срочно | CVE-2026-85706Готовый эксплойт | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabgitlab · gitlab · CWE-22 | Критическая10,0 | KEV | 91,4 % | 11 сент. 2026 г. |
85Срочно | CVE-2021-22175Готовый эксплойт | When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versionsgitlab · gitlab · CWE-918 | Критическая9,8 | KEV | 53,4 % | 11 июн. 2021 г. |
71На этой неделе | CVE-2021-39935Готовый эксплойт | An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 beforegitlab · gitlab · CWE-918 | Высокая7,5 | KEV | 35,6 % | 13 дек. 2021 г. |
65На этой неделе | CVE-2022-2992Готовый эксплойт | A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated usgitlab · gitlab · CWE-74 | Критическая9,9 | — | 86,2 % | 17 окт. 2022 г. |
62На этой неделе | CVE-2022-2884Proof of concept | A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authgitlab · gitlab · CWE-78 | Критическая9,9 | — | 75,7 % | 17 окт. 2022 г. |
62На этой неделе | CVE-2022-1162Proof of concept | A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.gitlab · gitlab · CWE-798 | Критическая9,8 | — | 75,6 % | 4 апр. 2022 г. |
58В плане | CVE-2022-2185Proof of concept | A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prgitlab · gitlab · CWE-78 | Высокая8,8 | — | 76,7 % | 1 июл. 2022 г. |
55В плане | CVE-2020-13340Эксплойта нет | An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Loggitlab · gitlab · CWE-79 | Высокая8,7 | — | 68,6 % | 8 окт. 2020 г. |
54В плане | CVE-2026-19478Proof of concept | Improper Control of Generation of Code ('Code Injection') in GitLabgitlab · gitlab · CWE-94 | Критическая9,1 | — | 60,2 % | 17 авг. 2026 г. |
54В плане | CVE-2018-14364Эксплойта нет | GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write acgitlab · gitlab · CWE-22 | Критическая9,8 | — | 50,1 % | 18 июл. 2018 г. |
51В плане | CVE-2023-2825Готовый эксплойт | An issue has been discovered in GitLab CE/EE affecting only version 16.0.0.gitlab · gitlab · CWE-22 | Высокая7,5 | — | 71,6 % | 26 мая 2023 г. |
50В плане | CVE-2023-2442Эксплойта нет | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 befogitlab · gitlab · CWE-79 | Средняя5,4 | — | 96,1 % | 7 июн. 2023 г. |
49В плане | CVE-2023-0050Эксплойта нет | An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.gitlab · gitlab · CWE-79 | Средняя5,4 | — | 92,4 % | 9 мар. 2023 г. |
49В плане | CVE-2022-1175Proof of concept | Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versiogitlab · gitlab · CWE-79 | Средняя6,1 | — | 82,0 % | 4 апр. 2022 г. |
49В плане | CVE-2024-1451Эксплойта нет | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabgitlab · gitlab · CWE-79 | Высокая8,7 | — | 51,5 % | 21 февр. 2024 г. |
47В плане | CVE-2022-1190Эксплойта нет | Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attagitlab · gitlab · CWE-79 | Средняя5,4 | — | 87,4 % | 4 апр. 2022 г. |
47В плане | CVE-2022-3265Эксплойта нет | A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 priogitlab · gitlab · CWE-79 | Средняя5,4 | — | 86,3 % | 9 нояб. 2022 г. |
45В плане | CVE-2021-4191Готовый эксплойт | An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2.gitlab · gitlab | Средняя5,3 | — | 80,0 % | 28 мар. 2022 г. |
43В плане | CVE-2021-22238Эксплойта нет | An issue has been discovered in GitLab affecting all versions starting with 13.3.gitlab · gitlab · CWE-79 | Средняя5,4 | — | 71,8 % | 20 авг. 2021 г. |
43В плане | CVE-2023-3364Эксплойта нет | Inefficient Regular Expression Complexity in GitLabgitlab · gitlab · CWE-1333 | Высокая7,5 | — | 44,5 % | 1 авг. 2023 г. |
43В плане | CVE-2022-0735Proof of concept | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 beforgitlab · gitlab | Критическая9,8 | — | 13,2 % | 28 мар. 2022 г. |
43В плане | CVE-2025-5121Эксплойта нет | Missing Authorization in GitLabgitlab · gitlab · CWE-862 | Критическая9,9 | — | 12,4 % | 20 июн. 2025 г. |
42В плане | CVE-2023-0921Эксплойта нет | Allocation of Resources Without Limits or Throttling in GitLabgitlab · gitlab · CWE-770 | Средняя4,3 | — | 84,4 % | 6 июн. 2023 г. |
- CVE-2021-22205100Срочно
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %gitlab · gitlab23 апр. 2021 г.
- CVE-2023-702897Срочно
Weak Password Recovery Mechanism for Forgotten Password in GitLab
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %gitlab · gitlab12 янв. 2024 г.
- CVE-2026-8570697Срочно
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 91 %gitlab · gitlab11 сент. 2026 г.
- CVE-2021-2217585Срочно
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 53 %gitlab · gitlab11 июн. 2021 г.
- CVE-2021-3993571На этой неделе
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 36 %gitlab · gitlab13 дек. 2021 г.
- CVE-2022-299265На этой неделе
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated us
КритическаяCVSS 9,9Готовый эксплойтEPSS 86 %gitlab · gitlab17 окт. 2022 г.
- CVE-2022-288462На этой неделе
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an auth
КритическаяCVSS 9,9Proof of conceptEPSS 76 %gitlab · gitlab17 окт. 2022 г.
- CVE-2022-116262На этой неделе
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.
КритическаяCVSS 9,8Proof of conceptEPSS 76 %gitlab · gitlab4 апр. 2022 г.
- CVE-2022-218558В плане
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 pr
ВысокаяCVSS 8,8Proof of conceptEPSS 77 %gitlab · gitlab1 июл. 2022 г.
- CVE-2020-1334055В плане
An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log
ВысокаяCVSS 8,7Эксплойта нетEPSS 69 %gitlab · gitlab8 окт. 2020 г.
- CVE-2026-1947854В плане
Improper Control of Generation of Code ('Code Injection') in GitLab
КритическаяCVSS 9,1Proof of conceptEPSS 60 %gitlab · gitlab17 авг. 2026 г.
- CVE-2018-1436454В плане
GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write ac
КритическаяCVSS 9,8Эксплойта нетEPSS 50 %gitlab · gitlab18 июл. 2018 г.
- CVE-2023-282551В плане
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0.
ВысокаяCVSS 7,5Готовый эксплойтEPSS 72 %gitlab · gitlab26 мая 2023 г.
- CVE-2023-244250В плане
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 befo
СредняяCVSS 5,4Эксплойта нетEPSS 96 %gitlab · gitlab7 июн. 2023 г.
- CVE-2023-005049В плане
An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.
СредняяCVSS 5,4Эксплойта нетEPSS 92 %gitlab · gitlab9 мар. 2023 г.
- CVE-2022-117549В плане
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versio
СредняяCVSS 6,1Proof of conceptEPSS 82 %gitlab · gitlab4 апр. 2022 г.
- CVE-2024-145149В плане
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
ВысокаяCVSS 8,7Эксплойта нетEPSS 51 %gitlab · gitlab21 февр. 2024 г.
- CVE-2022-119047В плане
Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an atta
СредняяCVSS 5,4Эксплойта нетEPSS 87 %gitlab · gitlab4 апр. 2022 г.
- CVE-2022-326547В плане
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prio
СредняяCVSS 5,4Эксплойта нетEPSS 86 %gitlab · gitlab9 нояб. 2022 г.
- CVE-2021-419145В плане
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2.
СредняяCVSS 5,3Готовый эксплойтEPSS 80 %gitlab · gitlab28 мар. 2022 г.
- CVE-2021-2223843В плане
An issue has been discovered in GitLab affecting all versions starting with 13.3.
СредняяCVSS 5,4Эксплойта нетEPSS 72 %gitlab · gitlab20 авг. 2021 г.
- CVE-2023-336443В плане
Inefficient Regular Expression Complexity in GitLab
ВысокаяCVSS 7,5Эксплойта нетEPSS 44 %gitlab · gitlab1 авг. 2023 г.
- CVE-2022-073543В плане
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 befor
КритическаяCVSS 9,8Proof of conceptEPSS 13 %gitlab · gitlab28 мар. 2022 г.
- CVE-2025-512143В плане
Missing Authorization in GitLab
КритическаяCVSS 9,9Эксплойта нетEPSS 12 %gitlab · gitlab20 июн. 2025 г.
- CVE-2023-092142В плане
Allocation of Resources Without Limits or Throttling in GitLab
СредняяCVSS 4,3Эксплойта нетEPSS 84 %gitlab · gitlab6 июн. 2023 г.