Security Lab

Множественные уязвимости в GitLab Community Edition (CE) and Enterprise Edition (EE)

Дата публикации:05.10.2020
Всего просмотров:1131
Опасность:
Высокая
Наличие исправления: Да
Количество уязвимостей:13
CVSSv3.1 рейтинг: 7.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]
6.1 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C]
7.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]
6.1 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C]
5.3 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C]
8.8 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
5.3 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C]
9.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
7.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
6.3 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C]
6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C]
6.3 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C]
6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]
CVE ID: CVE-2020-13333
CVE-2020-13332
CVE-2020-13335
CVE-2020-13334
CVE-2020-13327
Вектор эксплуатации: Удаленная
Воздействие: Межсайтовый скриптинг
Раскрытие важных данных
Обход ограничений безопасности
Компрометация системы
CWE ID: Нет данных
Наличие эксплоита: Нет данных
Уязвимые продукты: Gitlab Community Edition
GitLab Enterprise Edition
gitlab-runner
Уязвимые версии: Gitlab Community Edition версии 10.8.0, 10.8.7, 10.8.6, 10.8.4, 10.8.3, 10.8.2, 10.8.1, 10.8, 10.8.5, 11.11.8, 11.11.7, 11.11.5, 11.11.4, 11.11.3, 11.11.2, 11.10.8, 11.10.7, 11.11.1, 11.11.0, 11.10.6, 11.10.5, 11.10.4, 11.10.3, 11.10.2, 11.10.1, 11.9.12, 11.9.11, 11.9.10, 11.9.9, 11.8.10, 11.8.9, 11.10.0, 11.9.8, 11.9.7, 11.9.6, 11.9.5, 11.8.8, 11.8.7, 11.8.6, 11.7.12, 11.7.11, 11.6.11, 11.5.11, 11.9.4, 11.9.3, 11.9.2, 11.9.1, 11.9.0, 11.8.5, 11.8.4, 11.8.3, 11.8.2, 11.7.10, 11.7.9, 11.7.8, 11.7.7, 11.8.1, 11.8.0, 11.7.6, 11.7.5, 11.7.4, 11.6.10, 11.7.3, 11.7.2, 11.7.1, 11.7.0, 11.6.9, 11.6.8, 11.6.7, 11.6.6, 11.6.5, 11.6.4, 11.5.10, 11.5.9, 11.5.8, 11.5.7, 11.4.14, 11.6.3, 11.6.2, 11.6.1, 11.6.0, 11.5.6, 11.5.5, 11.5.4, 11.4.13, 11.4.12, 11.4.11, 11.3.14, 11.3.13, 11.5.3, 11.5.2, 11.5.1, 11.5.0, 11.4.10, 11.4.9, 11.4.8, 11.4.7, 11.4.6, 11.3.12, 11.3.11, 11.3.10, 11.4.5, 11.4.4, 11.3.9, 11.3.7, 11.2.8, 11.2.6, 11.4.2, 11.4.1, 11.4.0, 11.3.2, 11.3.1, 11.2.5, 11.1.8, 11.3.0, 11.2.4, 11.2.2, 11.1.7, 11.1.5, 11.2.0, 11.1.3, 11.1.0, 11.0.0, 11.2.1, 11.2, 11.0.6, 11.1.6, 11.2.3, 11.1.4, 11.0.5, 11.1.2, 11.1.1, 11.1, 11.0.4, 11.0.3, 11.0.2, 11.0, 11.4, 11.3.5, 11.3.6, 11.3.4, 11.3.3, 11.3, 11.2.7, 11.3.8, 11.4.3, 11.0.1, 12.10.14, 12.10.13, 12.10.12, 12.10.11, 12.9.10, 12.10.10, 12.10.9, 12.9.9, 12.10.8, 12.10.7, 12.9.8, 12.10.6, 12.10.5, 12.9.7, 12.10.4, 12.10.3, 12.10.2, 12.10.1, 12.9.6, 12.9.5, 12.8.10, 12.10.0, 12.9.4, 12.9.3, 12.8.9, 12.7.9, 12.9.2, 12.9.1, 12.8.8, 12.7.8, 12.9.0, 12.8.7, 12.8.6, 12.8.5, 12.8.4, 12.8.3, 12.8.2, 12.7.7, 12.6.8, 12.8.1, 12.8.0, 12.7.6, 12.6.7, 12.5.10, 12.7.5, 12.7.4, 12.6.6, 12.5.9, 12.7.2, 12.7.1, 12.7.0, 12.6.4, 12.5.7, 12.4.8, 12.6.3, 12.6.2, 12.6.1, 12.6.0, 12.5.6, 12.5.5, 12.4.7, 12.2.10, 12.1.15, 12.2.12, 12.1.17, 12.0.12, 12.2.11, 12.1.16, 12.0.10, 12.5.4, 12.4.6, 12.3.9, 12.5.3, 12.5.2, 12.4.5, 12.3.8, 12.3.7, 12.4.4, 12.5.1, 12.5.0, 12.4.3, 12.4.2, 12.4.1, 12.4.0, 12.3.6, 12.3.5, 12.3.4, 12.3.3, 12.3.2, 12.3.1, 12.2.9, 12.2.8, 12.2.7, 12.2.6, 12.1.14, 12.1.13, 12.1.12, 12.3.0, 12.2.5, 12.2.4, 12.1.11, 12.1.10, 12.1.9, 12.1.8, 12.1.6, 12.1.4, 12.0.9, 12.0.8, 12.0.6, 12.1.3, 12.1.2, 12.1.1, 12.0.4, 12.0.3, 12.0.2, 12.2.1, 12.2.0, 12.1.0, 12.0.1, 12.0.0, 12.2.3, 13.4.1, 13.4.0, 13.3.6, 13.3.5, 13.2.9, 13.1.11, 13.3.4, 13.2.8, 13.1.10, 13.3.3, 13.2.7, 13.1.9, 13.3.2, 13.3.1, 13.3.0, 13.2.6, 13.1.8, 13.0.14, 13.2.5, 13.1.7, 13.0.13, 13.2.4, 13.2.3, 13.1.6, 13.0.12, 13.2.2, 13.2.1, 13.1.5, 13.2.0, 13.1.4, 13.0.10, 13.1.3, 13.0.9, 13.0.8, 13.1.2, 13.0.7, 13.1.1, 13.1.0, 13.0.6, 13.0.5, 13.0.4, 13.0.3, 13.0.2, 13.0.1, 13.0.0, 10.7.0, 10.6.0, 10.2.7, 10.1.7, 10.3.0, 10.7.7, 10.6.6, 10.7.5, 10.7.4, 10.7.3, 10.5.8, 10.6.5, 10.7.2, 10.7.1, 10.6.4, 10.4.7, 10.5.7, 10.6.3, 10.6.2, 10.6.1, 10.6, 10.5, 10.2.8, 10.4, 10.2, 10.1, 10.7, 10.7.6, 10.3.8, 10.3.5, 10.3.6, 10.3.7, 10.5.0, 10.5.1, 10.5.2, 10.5.3, 10.5.4, 10.5.5, 10.4.0, 10.4.1, 10.4.2, 10.4.3, 10.4.4, 10.4.5, 10.5.6, 10.4.6, 10.3.9, 10.3.1, 10.3.2, 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.2.5, 10.1.4, 10.1.1, 10.1.2, 10.1.3, 10.1.5, 10.3.4, 10.2.6, 10.1.6, 10.3.3, 10.1.0, 10.3, 10.2.4, 8.11.0, 8.11.11, 8.11.10, 8.11.9, 8.11.8, 8.11.7, 8.11.6, 8.11.5, 8.11.4, 8.11.3, 8.11.2, 8.11.1, 8.12.2, 8.12.0, 8.12.13, 8.12.12, 8.12.11, 8.12.10, 8.12.9, 8.12.8, 8.12.7, 8.12.6, 8.12.5, 8.12.4, 8.12.3, 8.12.1, 8.13.4, 8.13.0, 8.13.12, 8.13.11, 8.13.10, 8.13.9, 8.13.8, 8.13.7, 8.13.6, 8.13.5, 8.13.3, 8.13.2, 8.13.1, 8.14.0, 8.14.10, 8.14.9, 8.14.8, 8.14.7, 8.14.6, 8.14.5, 8.14.4, 8.14.3, 8.14.2, 8.14.1, 8.15.0, 8.15.8, 8.15.7, 8.15.6, 8.15.5, 8.15.4, 8.15.3, 8.15.2, 8.15.1, 8.16.0, 8.16.9, 8.16.8, 8.16.7, 8.16.6, 8.16.5, 8.16.4, 8.16.3, 8.16.2, 8.16.1, 8.17.0, 8.17.8, 8.17.7, 8.17.6, 8.17.5, 8.17.4, 8.17.3, 8.17.2, 8.17.1, 9.5.5, 9.5.0, 9.4.0, 9.3.0, 9.2.4, 9.2.3, 9.1.6, 9.1.5, 9.0.9, 9.0.8, 9.2.0, 9.1.0, 9.0.0, 9.5.10, 9.4.7, 9.5.9, 9.5.8, 9.5.7, 9.5.6, 9.55, 9.3.11, 9.4.6, 9.5.4, 9.5.3, 9.5.2, 9.5.1, 9.5, 9.4.5, 9.0.13, 9.1.10, 9.2.10, 9.3.10, 9.4.4, 9.4.3, 9.4.2, 9.4.1, 9.4, 9.0.12, 9.1.9, 9.2.9, 9.3.9, 9.0.11, 9.1.8, 9.2.8, 9.3.8, 9.3.7, 9.3.6, 9.3.5, 9.3.4, 9.3.3, 9.3.2, 9.3.1, 9.3, 9.2.7, 9.2.6, 9.0.10, 9.1.7, 9.2.5, 9.2.2, 9.2.1, 9.2, 9.1.4, 9.0.7, 9.1.3, 9.1.2, 9.1.1, 9.1, 9.0.6, 9.0.5, 9.0.4, 9.0.3, 9.0.2, 9.0.1, 9.0, 10.0.0, 10.0.7, 10.0.6, 10.0.5, 10.0.4, 10.0.3, 10.0.2, 10.0.1, 10.0, 7.12.0, 7.12.2, 7.12.1, 7.12, 7.13.4, 7.13.3, 7.13.2, 7.13.1, 7.13.0, 7.13.5, 7.13, 7.14.2, 7.14.1, 7.14.0, 7.14.3, 7.14, 8.10.0, 8.9.0, 8.7.7, 8.6.9, 8.5.13, 8.4.11, 8.8.0, 8.6.8, 8.3.10, 8.3.9, 8.2.6, 8.2.5, 8.7.1, 8.7.0, 8.5.12, 8.4.10, 8.6.0, 8.5.0, 8.4.0, 8.3.0, 8.2.0, 8.1.0, 8.0.0, 8.17, 8.15, 8.14, 8.13, 8.12, 8.11, 8.10.13, 8.10.12, 8.10.11, 8.10.10, 8.10.9, 8.10.8, 8.10.7, 8.10.6, 8.10.5, 8.10.4, 8.10.3, 8.10.2, 8.10.1, 8.10, 8.9.11, 8.9.10, 8.9.9, 8.9.8, 8.9.7, 8.9.6, 8.9.5, 8.9.4, 8.9.3, 8.9.2, 8.9.1, 8.9, 8.8.9, 8.8.8, 8.7.9, 8.7.8, 8.8.7, 8.8.6, 8.8.5, 8.8.4, 8.8.3, 8.8.2, 8.8.1, 8.8, 8.7.6, 8.7.5, 8.7.4, 8.7.3, 8.7.2, 8.7, 8.6.7, 8.6.6, 8.6.5, 8.6.4, 8.6.3, 8.6.2, 8.6.1, 8.6, 8.5.11, 8.5.10, 8.5.9, 8.5.8, 8.5.7, 8.5.6, 8.5.5, 8.5.4, 8.5.3, 8.5.2, 8.5.1, 8.5, 8.4.9, 8.4.8, 8.4.7, 8.4.6, 8.4.5, 8.4.4, 8.4.3, 8.4.2, 8.4.1, 8.4, 8.3.8, 8.3.7, 8.3.6, 8.3.5, 8.3.4, 8.3.3, 8.3.2, 8.3.1, 8.3, 8.2.4, 8.2.3, 8.2.2, 8.2.1, 8.2, 8.1.4, 8.1.3, 8.1.2, 8.1.1, 8.0.5, 8.0.4, 8.0.3, 8.0.2, 8.0.1, 8.0
GitLab Enterprise Edition версии 10.8.6, 10.8.5, 10.8.4, 10.8.3, 10.8.2, 10.8.1, 10.8.0, 11.11.8, 11.11.7, 11.7.3, 11.5.10, 11.10.8, 11.11.4, 11.10.7, 11.11.3, 11.11.2, 11.10.6, 11.9.12, 11.11.0, 11.8.7, 11.8.6, 11.10.4, 11.10.3, 11.10.2, 11.10.1, 11.10.0, 11.9.10, 11.9.9, 11.9.8, 11.9.7, 11.9.6, 11.9.5, 11.9.3, 11.9.2, 11.9.1, 11.9.0, 11.8.10, 11.8.3, 11.8.2, 11.8.0, 11.7.12, 11.7.11, 11.7.10, 11.7.8, 11.7.7, 11.7.5, 11.7.2, 11.7.1, 11.7.0, 11.6.11, 11.6.10, 11.6.9, 11.6.8, 11.6.5, 11.6.4, 11.6.3, 11.6.2, 11.6.1, 11.6.0, 11.5.11, 11.5.8, 11.5.5, 11.5.3, 11.5.2, 11.5.1, 11.5.0, 11.4.9, 11.4.8, 11.4.7, 11.4.6, 11.4.5, 11.4.4, 11.4.3, 11.4.2, 11.4.1, 11.4.0, 11.3.14, 11.3.13, 11.3.11, 11.3.10, 11.3.9, 11.3.8, 11.3.7, 11.3.6, 11.3.5, 11.3.4, 11.3.3, 11.3.2, 11.3.1, 11.3.0, 11.2.8, 11.2.7, 11.2.6, 11.2.5, 11.2.4, 11.2.3, 11.2.2, 11.2.1, 11.2.0, 11.1.7, 11.1.6, 11.1.5, 11.1.4, 11.1.3, 11.1.2, 11.1.1, 11.1.0, 11.0.6, 11.0.5, 11.0.4, 11.0.3, 11.0.2, 11.0.1, 11.0.0, 12.10.14, 12.10.13, 12.10.12, 12.10.11, 12.9.10, 12.10.8, 12.10.7, 12.9.8, 12.10.6, 12.10.5, 12.10.4, 12.9.6, 12.10.2, 12.10.1, 12.9.5, 12.8.10, 12.10.0, 12.9.4, 12.9.3, 12.9.2, 12.9.1, 12.9.0, 12.8.9, 12.8.7, 12.8.6, 12.8.5, 12.8.4, 12.8.3, 12.8.2, 12.8.1, 12.8.0, 12.7.9, 12.6.7, 12.7.2, 12.5.9, 12.7.4, 12.7.5, 12.7.3, 12.7.1, 12.7.0, 12.6.6, 12.6.5, 12.6.4, 12.6.2, 12.6.1, 12.6.0, 12.5.8, 12.5.5, 12.5.4, 12.5.3, 12.5.1, 12.5.0, 12.4.8, 12.3.9, 12.2.11, 12.1.14, 12.1.12, 12.0.12, 12.0.10, 12.4.5, 12.4.3, 12.4.2, 12.4.1, 12.4.0, 12.3.7, 12.3.4, 12.3.2, 12.3.1, 12.3.0, 12.2.8, 12.2.7, 12.2.6, 12.1.10, 12.1.9, 12.0.9, 12.2.5, 12.2.4, 12.2.2, 12.1.5, 12.1.4, 12.1.3, 12.1.2, 12.1.1, 12.0.7, 12.0.6, 12.2.1, 12.2.0, 12.2.3, 12.0.2, 12.0.1, 12.0.0, 13.3.6, 13.3.5, 13.4.0, 13.3.4, 13.2.8, 13.1.10, 13.3.3, 13.2.7, 13.1.9, 13.3.2, 13.3.1, 13.3.0, 13.2.6, 13.2.5, 13.1.8, 13.1.7, 13.0.14, 13.0.13, 13.2.4, 13.2.3, 13.1.6, 13.0.12, 13.0.11, 13.2.2, 13.1.5, 13.2.0, 13.1.0, 13.0.10, 13.1.3, 13.0.9, 13.1.2, 13.0.8, 13.0.7, 13.1.1, 13.0.6, 13.0.4, 13.0.3, 13.0.1, 13.0.0, 10.7.7, 10.7.6, 10.7.5, 10.7.4, 10.7.3, 10.7.2, 10.7.1, 10.7.0, 10.6.6, 10.6.5, 10.6.4, 10.6.3, 10.6.2, 10.6.1, 10.6.0, 10.5.8, 10.5.7, 10.5.6, 10.5.5, 10.5.4, 10.5.3, 10.5.2, 10.5.1, 10.5.0, 10.4.7, 10.4.6, 10.4.5, 10.4.4, 10.4.3, 10.4.2, 10.4.1, 10.4.0, 10.3.9, 10.3.8, 10.3.7, 10.3.6, 10.3.5, 10.3.4, 10.3.3, 10.3.2, 10.3.1, 10.3.0, 10.2.8, 10.2.7, 10.2.6, 10.2.5, 10.2.4, 10.2.3, 10.2.2, 10.2.1, 10.2.0, 10.1.7, 10.1.6, 10.1.5, 10.1.4, 10.1.3, 10.1.2, 10.1.1, 10.1.0, 8.11.9, 8.11.8, 8.11.7, 8.11.6, 8.11.5, 8.11.4, 8.11.3, 8.11.2, 8.11.1, 8.11.11, 8.11.10, 8.11.0, 8.12.7, 8.12.6, 8.12.5, 8.12.4, 8.12.3, 8.12.2, 8.12.1, 8.12.12, 8.12.11, 8.12.10, 8.12.9, 8.12.8, 8.12.0, 8.13.12, 8.13.11, 8.13.10, 8.13.9, 8.13.8, 8.13.7, 8.13.6, 8.13.5, 8.13.4, 8.13.3, 8.13.2, 8.13.1, 8.13.0, 8.14.10, 8.14.9, 8.14.8, 8.14.7, 8.14.6, 8.14.5, 8.14.4, 8.14.3, 8.14.2, 8.14.1, 8.14.0, 8.15.8, 8.15.7, 8.15.6, 8.15.5, 8.15.4, 8.15.3, 8.15.2, 8.15.1, 8.15.0, 8.16.9, 8.16.8, 8.16.7, 8.16.6, 8.16.5, 8.16.4, 8.16.3, 8.16.2, 8.16.1, 8.16.0, 8.17.8, 8.17.7, 8.17.6, 8.17.5, 8.17.4, 8.17.3, 8.17.2, 8.17.1, 8.17.0, 9.5.10, 9.5.9, 9.5.8, 9.5.7, 9.5.6, 9.5.5, 9.5.4, 9.5.3, 9.5.2, 9.5.1, 9.5.0, 9.4.7, 9.4.6, 9.4.5, 9.4.4, 9.4.3, 9.4.2, 9.4.1, 9.4.0, 9.3.11, 9.3.10, 9.3.9, 9.3.8, 9.3.7, 9.3.6, 9.3.5, 9.3.4, 9.3.3, 9.3.2, 9.3.1, 9.3.0, 9.2.10, 9.2.9, 9.2.8, 9.2.7, 9.2.6, 9.2.5, 9.2.4, 9.2.3, 9.2.2, 9.2.1, 9.2.0, 9.1.10, 9.1.9, 9.1.8, 9.1.7, 9.1.6, 9.1.5, 9.1.4, 9.1.3, 9.1.2, 9.1.1, 9.1.0, 9.0.13, 9.0.12, 9.0.11, 9.0.10, 9.0.9, 9.0.8, 9.0.7, 9.0.6, 9.0.5, 9.0.4, 9.0.3, 9.0.2, 9.0.1, 9.0.0, 10.0.7, 10.0.5, 10.0.4, 10.0.3, 10.0.2, 10.0.1, 10.0.0, 7.12.2, 7.12.1, 7.12.0, 7.13.3, 7.13.2, 7.13.1, 7.13.0, 7.14.3, 7.14.2, 7.14.1, 7.14.0, 8.10.12, 8.10.11, 8.10.10, 8.10.9, 8.10.8, 8.10.7, 8.10.6, 8.10.5, 8.10.4, 8.10.3, 8.10.2, 8.10.1, 8.9.10, 8.9.9, 8.9.8, 8.9.7, 8.9.6, 8.9.5, 8.9.4, 8.9.3, 8.9.2, 8.9.1, 8.8.9, 8.8.8, 8.8.7, 8.8.6, 8.8.5, 8.8.4, 8.8.3, 8.8.2, 8.8.1, 8.7.9, 8.7.8, 8.7.7, 8.7.6, 8.7.5, 8.7.4, 8.7.3, 8.7.2, 8.7.1, 8.6.9, 8.6.8, 8.6.7, 8.6.6, 8.6.5, 8.6.4, 8.6.3, 8.6.2, 8.6.1, 8.5.13, 8.5.12, 8.5.11, 8.5.10, 8.5.9, 8.5.8, 8.5.7, 8.5.6, 8.5.5, 8.5.4, 8.5.3, 8.5.2, 8.5.1, 8.4.11, 8.4.10, 8.4.9, 8.4.8, 8.4.7, 8.4.6, 8.4.5, 8.4.4, 8.4.3, 8.4.2, 8.4.1, 8.3.10, 8.3.9, 8.3.8, 8.3.7, 8.3.6, 8.3.5, 8.3.4, 8.3.3, 8.3.2, 8.3.1, 8.2.6, 8.2.5, 8.2.4, 8.2.3, 8.2.2, 8.2.1, 8.1.4, 8.1.3, 8.1.2, 8.1.1, 8.0.6, 8.0.5, 8.0.4, 8.0.3, 8.0.2, 8.0.1, 8.10.0, 8.9.0, 8.8.0, 8.7.0, 8.6.0, 8.5.0, 8.4.0, 8.3.0, 8.2.0, 8.1.0, 8.0.0
gitlab-runner версии 12.4.1, 12.4.0, 12.3.0, 12.2.0, 12.1.0, 12.0.2, 12.9.0, 12.10.1, 12.8.0, 12.7.1, 12.6.0, 12.5.0, 12.10.2, 13.4.1, 13.4.0, 13.0.0, 13.2.1, 13.2, 13.3, 13.4
Описание:

Множественные уязвимости в GitLab Community Edition (CE) and Enterprise Edition (EE)

URL производителя: https://docs.gitlab.com
Решение: Установите исправление с сайта производителя.
Ссылки: https://www.cybersecurity-help.cz/vdb/SB2020100507