目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

GitLab 厂商漏洞列表 / CVE 中文分析 1012

GitLab 厂商相关 1012 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

GitLab 提供基于 Web 的 DevOps 平台,核心用于代码托管、CI/CD 及项目管理。其历史漏洞多涉及远程代码执行、越权访问及跨站脚本攻击,累计收录 CVE 达 1012 条。平台内置安全扫描功能,支持 SAST 与 DAST 集成,助力开发者在流水线中识别风险。尽管存在安全挑战,其持续更新的补丁机制与透明披露政策,使其成为企业构建安全软件供应链的重要基础设施。

CVE IDタイトルCVSS深刻度公開日
CVE-2024-2880 Improper Access Control in GitLab — GitLabCWE-284 2.7 Low2024-07-11
CVE-2024-5257 Improper Access Control in GitLab — GitLabCWE-284 4.9 Medium2024-07-11
CVE-2024-5470 Improper Access Control in GitLab — GitLabCWE-284 3.8 Low2024-07-11
CVE-2024-6385 Improper Access Control in GitLab — GitLabCWE-284 9.6 Critical2024-07-11
CVE-2024-2177 Improper Restriction of Rendered UI Layers or Frames in GitLab — GitLabCWE-1021 6.8 Medium2024-07-09
CVE-2024-1493 Uncontrolled Resource Consumption in GitLab — GitLabCWE-1333 6.5 Medium2024-06-26
CVE-2024-1816 Uncontrolled Resource Consumption in GitLab — GitLabCWE-400 5.3 Medium2024-06-26
CVE-2024-2191 Improper Access Control in GitLab — GitLabCWE-284 5.3 Medium2024-06-26
CVE-2024-3115 Exposure of Sensitive Information to an Unauthorized Actor in GitLab — GitLabCWE-862 4.3 Medium2024-06-26
CVE-2024-3959 Improper Authorization in GitLab — GitLabCWE-285 6.5 Medium2024-06-26
CVE-2024-4011 Improper Access Control in GitLab — GitLabCWE-863 3.1 Low2024-06-26
CVE-2024-4557 Uncontrolled Resource Consumption in GitLab — GitLabCWE-400 6.5 Medium2024-06-26
CVE-2024-4901 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab — GitLabCWE-79 8.7 High2024-06-26
CVE-2024-5655 Improper Access Control in GitLab — GitLabCWE-284 9.6 Critical2024-06-26
CVE-2024-5430 Improper Access Control in GitLab — GitLabCWE-284 6.8 Medium2024-06-26
CVE-2024-6323 Improper Isolation or Compartmentalization in GitLab — GitLabCWE-863 7.5 High2024-06-26
CVE-2024-5469 Uncontrolled Resource Consumption in GitLab — GitLabCWE-754 3.1 Low2024-06-14
CVE-2024-1736 Uncontrolled Resource Consumption in GitLab — GitLabCWE-1333 6.5 Medium2024-06-12
CVE-2024-1495 Uncontrolled Resource Consumption in GitLab — GitLabCWE-1333 6.5 Medium2024-06-12
CVE-2024-1963 Uncontrolled Resource Consumption in GitLab — GitLabCWE-1333 6.5 Medium2024-06-12
CVE-2024-4201 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab — GitLabCWE-79 4.4 Medium2024-06-12
CVE-2024-5318 Missing Authorization in GitLab — GitLabCWE-862 4.0 Medium2024-05-24
CVE-2023-6502 Inefficient Regular Expression Complexity in GitLab — GitLabCWE-1333 4.3 Medium2024-05-23
CVE-2023-7045 Cross-Site Request Forgery (CSRF) in GitLab — GitLabCWE-352 5.4 Medium2024-05-23
CVE-2024-1947 Improper Handling of Highly Compressed Data (Data Amplification) in GitLab — GitLabCWE-409 4.3 Medium2024-05-23
CVE-2024-5258 Authorization Bypass Through User-Controlled Key in GitLab — GitLabCWE-639 4.4 Medium2024-05-23
CVE-2024-2874 Allocation of Resources Without Limits or Throttling in GitLab — GitLabCWE-770 6.5 Medium2024-05-23
CVE-2024-4835 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab — GitLabCWE-79 8.0 High2024-05-23
CVE-2023-6682 Inefficient Regular Expression Complexity in GitLab — GitLabCWE-1333 6.5 Medium2024-05-09
CVE-2023-6688 Inefficient Regular Expression Complexity in GitLab — GitLabCWE-1333 6.5 Medium2024-05-09

本页汇总了 GitLab 厂商截至目前公开的全部 1012 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。