VYPR

Bitnami package

gitlab

pkg:bitnami/gitlab

Vulnerabilities (1,154)

  • CVE-2026-13210HigSep 15, 2026
    affected >= 15.7.0, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to access CI/CD variables outside their intended environment scope due

  • CVE-2026-12910MedSep 15, 2026
    affected >= 18.6.0, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to bypass SAML SSO sign-in restrictions and authenticate without SSO du

  • CVE-2026-87719CriSep 12, 2026
    affected >= 18.3.0, < 19.1.8fixed 19.1.8

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced

  • CVE-2026-85706CriKEVSep 12, 2026
    affected >= 18.7.0, < 18.11.12fixed 18.11.12

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Git

  • CVE-2026-7487LowAug 26, 2026
    affected >= 13.1.0, < 19.1.7fixed 19.1.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with reporter-role permissions who authored a merge request could have reset merge request

  • CVE-2026-77801MedAug 26, 2026
    affected >= 12.8.0, < 19.1.7fixed 19.1.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, could have allowed an authenticated user to cause a denial of service affecting background job processing, due

  • CVE-2026-3035MedAug 26, 2026
    affected >= 11.3.0, < 19.1.7fixed 19.1.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with project Maintainer permissions could have accessed the terminal of a protected environ

  • CVE-2026-18252HigAug 26, 2026
    affected >= 18.9.0, < 19.1.7fixed 19.1.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due

  • CVE-2026-15387MedAug 26, 2026
    affected >= 19.1.0, < 19.1.7fixed 19.1.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have influenced the execution environment of Pipeline

  • CVE-2025-10903MedAug 26, 2026
    affected >= 11.10.0, < 19.1.7fixed 19.1.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have caused denial of service, due to an unbounded loop triggered by specially craft

  • CVE-2026-10053HigAug 23, 2026
    affected >= 18.8.0, < 19.0.6fixed 19.0.6

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability

  • CVE-2026-19650HigAug 17, 2026
    affected >= 18.2.0, < 18.11.11fixed 18.11.11

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to im

  • CVE-2026-19478CriAug 17, 2026
    affected >= 18.2.0, < 18.11.11fixed 18.11.11

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user

  • CVE-2026-6821MedAug 12, 2026
    affected >= 12.0.0, < 19.0.6fixed 19.0.6

    GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to bypass IP-based access restrictions and read limited merge request info

  • CVE-2026-4879MedAug 12, 2026
    affected >= 16.0.0, < 19.0.6fixed 19.0.6

    GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to view external status check configuratio

  • CVE-2026-19228HigAug 12, 2026
    affected >= 19.1.0, < 19.1.4fixed 19.1.4

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of ident

  • CVE-2026-18433MedAug 12, 2026
    affected >= 19.1.0, < 19.1.4fixed 19.1.4

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to read policy configuration belonging to a namespace they were not authorized to access, due t

  • CVE-2026-16494HigAug 12, 2026
    affected >= 19.1.0, < 19.1.4fixed 19.1.4

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization

  • CVE-2026-15217HigAug 12, 2026
    affected >= 18.2.0, < 19.0.6fixed 19.0.6

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled values rendered in tab

  • CVE-2026-15216HigAug 12, 2026
    affected >= 18.2.0, < 19.0.6fixed 19.0.6

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled data rendered in pagin

Page 2 of 58