VYPR

Bitnami package

gitlab

pkg:bitnami/gitlab

Vulnerabilities (1,131)

  • CVE-2024-3115MedJun 27, 2024
    affected >= 16.0.0, < 16.11.5fixed 16.11.5

    An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

  • CVE-2024-2191MedJun 27, 2024
    affected >= 16.9.0, < 16.11.5fixed 16.11.5

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

  • CVE-2024-1816MedJun 27, 2024
    affected >= 12.0.0, < 16.11.5fixed 16.11.5

    An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file.

  • CVE-2024-1493MedJun 27, 2024
    affected >= 9.2.0, < 16.11.5fixed 16.11.5

    An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, with the processing logic for generating link in dependency files can lead to a regular expression DoS a

  • CVE-2024-5469LowJun 14, 2024
    affected >= 16.10.0, < 16.10.6fixed 16.10.6

    DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests.

  • CVE-2024-4201MedJun 12, 2024
    affected >= 5.1.0, < 16.10.7fixed 16.10.7

    A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be mad

  • CVE-2024-1963MedJun 12, 2024
    affected >= 8.4.0, < 16.10.7fixed 16.10.7

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's Asana integration allowed an attacker to potentially cause a regular e

  • CVE-2024-1736MedJun 12, 2024
    affected >= 15.8.0, < 16.10.7fixed 16.10.7

    An issue has been discovered in GitLab CE/EE affecting all versions prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's CI/CD pipeline editor could allow for denial of service attacks through maliciously craf

  • CVE-2024-1495MedJun 12, 2024
    affected >= 13.1.0, < 16.10.7fixed 16.10.7

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.1 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. It was possible for an attacker to cause a denial of service using maliciously crafted file.

  • CVE-2024-5318MedMay 24, 2024
    affected >= 11.11.0, < 16.10.6fixed 16.10.6

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from 16.11 prior to 16.11.3, and starting from 17.0 prior to 17.0.1. A Guest user can view dependency lists of private projects through job artifacts.

  • CVE-2024-5258MedMay 23, 2024
    affected >= 16.10.0, < 16.10.6fixed 16.10.6

    An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.

  • CVE-2024-1947MedMay 23, 2024
    affected >= 13.2.4, < 16.10.6fixed 16.10.6

    A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls.

  • CVE-2023-7045MedMay 23, 2024
    affected >= 13.11.0, < 16.10.6fixed 16.10.6

    A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging this vulnerability, an attacker could exfiltrate anti-CSRF tokens via the Kubernetes Agent Server (KAS).

  • CVE-2023-6502MedMay 23, 2024
    affected < 16.10.6fixed 16.10.6

    A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. It is possible for an attacker to cause a denial of service using a crafted wiki page.

  • CVE-2024-4835HigMay 23, 2024
    affected >= 15.11.0, < 16.10.6fixed 16.10.6

    A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

  • CVE-2024-2874MedMay 23, 2024
    affected < 16.10.6fixed 16.10.6

    An issue has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. A runner registered with a crafted description has the potential to disrupt the loading of targeted GitLab web resources.

  • CVE-2024-4597MedMay 14, 2024
    affected >= 16.7.0, < 16.9.7fixed 16.9.7

    An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.

  • CVE-2024-4539MedMay 14, 2024
    affected >= 15.4.0, < 16.9.7fixed 16.9.7

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 where abusing the API to filter branch and tags could lead to Denial of Service.

  • CVE-2024-2651MedMay 14, 2024
    affected < 16.9.7fixed 16.9.7

    An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. It was possible for an attacker to cause a denial of service using maliciously crafted markdown con

  • CVE-2024-2454MedMay 14, 2024
    affected >= 15.11.0, < 16.9.7fixed 16.9.7

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. The pins endpoint is susceptible to DoS through a crafted request.

Page 23 of 57