VYPR

gitlab-org/gitlab-ee

by GitLab Inc.

Source repositories

CVEs (297)

  • CVE-2024-9631HigFeb 5, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.

  • CVE-2024-6323HigJun 27, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.

  • CVE-2023-4812HigJan 12, 2024
    risk 0.49cvss 7.6epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously…

  • CVE-2023-3994HigAug 2, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads…

  • CVE-2023-2198HigJun 7, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads…

  • CVE-2021-22215HigJun 8, 2021
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects

  • CVE-2020-13263HigJun 19, 2020
    risk 0.49cvss 7.5epss 0.01

    An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.

  • CVE-2020-10953HigMar 27, 2020
    risk 0.49cvss 7.5epss 0.02

    In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.

  • CVE-2020-10073HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page.

  • CVE-2020-7972HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).

  • CVE-2020-7969HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.

  • CVE-2020-7968HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.

  • CVE-2020-7966HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.02

    GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.

  • CVE-2019-19629HigJan 5, 2020
    risk 0.49cvss 7.5epss 0.01

    In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.

  • CVE-2018-19584HigJul 10, 2019
    risk 0.49cvss 7.5epss 0.02

    GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups.

  • CVE-2018-19581HigJul 10, 2019
    risk 0.49cvss 7.5epss 0.01

    GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.

  • CVE-2019-9220HigApr 17, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption.

  • CVE-2018-20144HigMar 28, 2019
    risk 0.49cvss 7.5epss 0.02

    GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorrect Access Control.

  • CVE-2023-5356HigJan 12, 2024
    risk 0.48cvss 7.3epss 0.01

    Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as…

  • CVE-2023-6680HigDec 15, 2023
    risk 0.48cvss 7.4epss 0.00

    An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard…

Page 3 of 15