VYPR

Bitnami package

gitlab

pkg:bitnami/gitlab

Vulnerabilities (1,131)

  • CVE-2026-13320HigJul 8, 2026
    affected >= 15.7.0, < 18.11.7fixed 18.11.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to execute arbitrary scripts in another user's browser session due to

  • CVE-2026-13151Jul 8, 2026
    affected >= 16.10.0, < 18.11.7fixed 18.11.7

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-11827MedJul 8, 2026
    affected >= 9.5.0, < 18.11.7fixed 18.11.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to obtain another user's stored credentia

  • CVE-2025-12506LowJul 8, 2026
    affected >= 16.5.0, < 18.11.7fixed 18.11.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web interfac

  • CVE-2026-8330MedJun 25, 2026
    affected >= 9.3.0, < 18.11.6fixed 18.11.6

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed sensitive information to be written to application logs due to insufficient filtering in a CI

  • CVE-2026-5952MedJun 25, 2026
    affected >= 17.11.0, < 18.11.6fixed 18.11.6

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass package protection rules an

  • CVE-2026-5796MedJun 25, 2026
    affected >= 13.6.0, < 18.11.6fixed 18.11.6

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with Reporter-level group permissions to view package metadata from pr

  • CVE-2026-5309MedJun 25, 2026
    affected >= 18.6.0, < 18.11.6fixed 18.11.6

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to read or modify another group's virtual registry cleanup policy setting

  • CVE-2026-3176LowJun 25, 2026
    affected >= 18.6.0, < 18.11.6fixed 18.11.6

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited permissions to access project information due to insufficien

  • CVE-2026-2238MedJun 25, 2026
    affected >= 17.5.0, < 18.11.6fixed 18.11.6

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to view confidential issue references on public projects due to impr

  • CVE-2026-1606MedJun 25, 2026
    affected >= 14.8.0, < 18.11.6fixed 18.11.6

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation.

  • CVE-2026-12635NonJun 25, 2026
    affected >= 8.3.0, < 18.11.6fixed 18.11.6

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to make requests to internal network r

  • CVE-2026-12053HigJun 25, 2026
    affected >= 19.1.0, < 19.1.1fixed 19.1.1

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows.

  • CVE-2026-11379MedJun 25, 2026
    affected >= 13.11.0, < 18.11.6fixed 18.11.6

    GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in which incorrect authorization in DAST site profile management could allow a user with Developer role to exfiltrate DAST site profile s

  • CVE-2026-10712HigJun 25, 2026
    affected >= 18.10.0, < 18.11.6fixed 18.11.6

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to

  • CVE-2026-10086HigJun 25, 2026
    affected >= 16.4.0, < 18.11.6fixed 18.11.6

    GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in

  • CVE-2026-0934LowJun 25, 2026
    affected >= 17.9.0, < 18.11.6fixed 18.11.6

    GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with custom role permissions to view, create, or delete protected environ

  • CVE-2026-9694LowJun 11, 2026
    affected >= 15.9.0, < 18.10.8fixed 18.10.8

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, could have allowed an unauthenticated user to impersonate the GitLab Support Bot and inject arbitrary conten

  • CVE-2026-9204MedJun 11, 2026
    affected >= 18.10.0, < 18.10.8fixed 18.10.8

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to read arbitrary files from the Gitaly server and access internal

  • CVE-2026-8589HigJun 11, 2026
    affected >= 13.1.4, < 18.10.8fixed 18.10.8

    GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to add unauthorized email addresses to a targeted user's account due

Page 3 of 57