VYPR

Bitnami package

gitlab

pkg:bitnami/gitlab

Vulnerabilities (1,154)

  • CVE-2026-93577CriSep 24, 2026
    affected >= 19.2.0, < 19.2.7fixed 19.2.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overfl

  • CVE-2026-92874MedSep 24, 2026
    affected >= 18.3.0, < 19.2.7fixed 19.2.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with an MCP-scoped token to perform actions beyond the intended scope o

  • CVE-2026-92628LowSep 24, 2026
    affected >= 18.6.0, < 19.2.7fixed 19.2.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race condition, the MCP search tool's shared state handling could have caused search results to be returned under an incorrect us

  • CVE-2026-92530MedSep 24, 2026
    affected >= 19.1.0, < 19.2.7fixed 19.2.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to spoof merge request authorship and attribute content to arbitrary ex

  • CVE-2026-92529MedSep 24, 2026
    affected >= 19.1.0, < 19.2.7fixed 19.2.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass admin-configured AI tool governa

  • CVE-2026-92470HigSep 24, 2026
    affected >= 18.7.0, < 19.2.7fixed 19.2.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to access sensitive CI/CD variable values from debug-mode job traces throu

  • CVE-2026-89078CriSep 24, 2026
    affected >= 19.2.0, < 19.2.7fixed 19.2.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free iss

  • CVE-2026-86341MedSep 16, 2026
    affected >= 17.1.0, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user with Owner or Maintainer permissions could have silently disabled protected environment dep

  • CVE-2026-8030MedSep 16, 2026
    affected >= 13.0.0, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to prevent another user from modifying their group settings due to impr

  • CVE-2026-7514MedSep 16, 2026
    affected >= 13.9.0, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that an authenticated user with developer-role permissions could substitute package file content and hide packages from their owners due to im

  • CVE-2026-79708HigSep 16, 2026
    affected >= 19.0.0, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to execute a policy test pipeline on projects

  • CVE-2026-78252HigSep 16, 2026
    affected >= 15.3.0, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user could have induced a targeted user to perform unintended state-changing HTTP requests du

  • CVE-2026-3855LowSep 16, 2026
    affected >= 18.2.7, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user with project-level permissions to access restricted file contents on

  • CVE-2026-1168HigSep 16, 2026
    affected >= 18.4.6, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation limi

  • CVE-2026-19619MedSep 16, 2026
    affected >= 19.0.0, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in the context of a targeted user's s

  • CVE-2026-16794MedSep 16, 2026
    affected >= 18.11.0, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user with the Security Manager role to execute arbitrary CI/CD jobs and access

  • CVE-2025-14871HigSep 16, 2026
    affected >= 18.4.6, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation limi

  • CVE-2024-11222MedSep 16, 2026
    affected >= 13.0.0, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed a developer user to perform actions in the context of another user's merge request commit due

  • CVE-2026-88765HigSep 15, 2026
    affected >= 12.3.0, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a specially crafted Git project export to ov

  • CVE-2026-82837MedSep 15, 2026
    affected >= 10.1.0, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials and tokens without transiting the expected

Page 1 of 58