VYPR

gitlab-org/gitlab-ee

by GitLab Inc.

Source repositories

CVEs (295)

  • CVE-2022-1188LowApr 4, 2022
    risk 0.17cvss 3.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.

  • CVE-2023-3511LowDec 15, 2023
    risk 0.13cvss 2.0epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private…

  • CVE-2026-16553MedJul 29, 2026
    risk 0.00cvss 5.4epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of…

  • CVE-2026-15831MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization…

  • CVE-2026-15077MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to access information from unauthorized projects due to improper neutralization of untrusted…

  • CVE-2026-13113MedJul 29, 2026
    risk 0.00cvss 6.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to merge code into a protected branch without the required approvals due…

  • CVE-2026-8472MedJul 8, 2026
    risk 0.00cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with minimal access permissions to read work item metadata from private…

  • CVE-2026-6896HigJul 8, 2026
    risk 0.00cvss 8.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another…

  • CVE-2026-5309MedJun 25, 2026
    risk 0.00cvss 5.4epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to read or modify another group's virtual registry cleanup policy…

  • CVE-2026-3176LowJun 25, 2026
    risk 0.00cvss 3.1epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited permissions to access project information due to…

  • CVE-2026-12053HigJun 25, 2026
    risk 0.00cvss 8.6epss 0.01

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows.

  • CVE-2026-11379MedJun 25, 2026
    risk 0.00cvss 5.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in which incorrect authorization in DAST site profile management could allow a user with Developer role to exfiltrate DAST site profile…

  • CVE-2026-10086HigJun 25, 2026
    risk 0.00cvss 8.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in…

  • CVE-2026-0934LowJun 25, 2026
    risk 0.00cvss 3.8epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with custom role permissions to view, create, or delete protected…

  • CVE-2023-5106HigOct 2, 2023
    risk 0.00cvss 8.2epss 0.01

    An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.

Page 15 of 15