VYPR

gitlab-org/gitlab-ee

by GitLab Inc.

Source repositories

CVEs (295)

  • CVE-2022-4335MedJan 27, 2023
    risk 0.28cvss 4.3epss 0.01

    A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host.

  • CVE-2022-3413MedNov 10, 2022
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allowed Developers to view the project's Audit Events and Developers or Maintainers to view the group's Audit…

  • CVE-2022-3351MedOct 17, 2022
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A user's primary email may be disclosed to an attacker through group member events…

  • CVE-2022-3030MedOct 17, 2022
    risk 0.28cvss 4.3epss 0.01

    An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.

  • CVE-2021-39930MedDec 13, 2021
    risk 0.28cvss 4.3epss 0.01

    Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an attacker to access a user's custom project and group templates

  • CVE-2021-39916MedDec 13, 2021
    risk 0.28cvss 4.3epss 0.01

    Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from…

  • CVE-2021-39889MedOct 5, 2021
    risk 0.28cvss 4.3epss 0.01

    In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

  • CVE-2021-39888MedOct 5, 2021
    risk 0.28cvss 4.3epss 0.01

    In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge…

  • CVE-2021-39884MedOct 5, 2021
    risk 0.28cvss 4.3epss 0.01

    In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

  • CVE-2021-39883MedOct 4, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.

  • CVE-2021-22259MedOct 4, 2021
    risk 0.28cvss 4.3epss 0.01

    A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

  • CVE-2021-22251MedAug 23, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings

  • CVE-2021-22249MedAug 23, 2021
    risk 0.28cvss 4.3epss 0.01

    A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group

  • CVE-2021-22233MedJul 7, 2021
    risk 0.28cvss 4.3epss 0.01

    An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details

  • CVE-2021-22169MedMar 24, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.

  • CVE-2020-13349MedNov 17, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted in the Advanced Search feature susceptible to catastrophic backtracking. Affected versions are >=8.12, <13.3.9,>=13.4, <13.4.5,>=13.5,…

  • CVE-2020-7967MedFeb 5, 2020
    risk 0.28cvss 4.3epss 0.01

    GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).

  • CVE-2019-19311MedJan 3, 2020
    risk 0.28cvss 5.4epss 0.01

    GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.

  • CVE-2018-20488MedDec 30, 2019
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.

  • CVE-2018-19582MedJul 10, 2019
    risk 0.28cvss 4.3epss 0.01

    GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

Page 11 of 15