VYPR

GitLab Workhorse

by GitLab Inc.

CVEs (3)

  • CVE-2021-22190HigApr 12, 2021
    risk 0.55cvss 8.5epss 0.01

    A path traversal vulnerability via the GitLab Workhorse in all versions of GitLab could result in the leakage of a JWT token

  • CVE-2020-6833HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.

  • CVE-2018-19583MedJul 10, 2019
    risk 0.42cvss 6.5epss 0.02

    GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.