gitlab-org/gitlab-ee
by GitLab Inc.
Source repositories
CVEs (297)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-9631 | Hig | 0.49 | 7.5 | 0.01 | Feb 5, 2025 | An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow. | ||
| CVE-2024-6323 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2024 | Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project. | ||
| CVE-2023-4812 | Hig | 0.49 | 7.6 | 0.01 | Jan 12, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously… | ||
| CVE-2023-3994 | Hig | 0.49 | 7.5 | 0.01 | Aug 2, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads… | ||
| CVE-2023-2198 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads… | ||
| CVE-2021-22215 | Hig | 0.49 | 7.5 | 0.01 | Jun 8, 2021 | An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects | ||
| CVE-2020-13263 | Hig | 0.49 | 7.5 | 0.01 | Jun 19, 2020 | An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions. | ||
| CVE-2020-10953 | Hig | 0.49 | 7.5 | 0.02 | Mar 27, 2020 | In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue. | ||
| CVE-2020-10073 | Hig | 0.49 | 7.5 | 0.01 | Mar 13, 2020 | GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page. | ||
| CVE-2020-7972 | Hig | 0.49 | 7.5 | 0.01 | Feb 5, 2020 | GitLab EE 12.2 has Insecure Permissions (issue 2 of 2). | ||
| CVE-2020-7969 | Hig | 0.49 | 7.5 | 0.01 | Feb 5, 2020 | GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure. | ||
| CVE-2020-7968 | Hig | 0.49 | 7.5 | 0.01 | Feb 5, 2020 | GitLab EE 8.0 through 12.7.2 has Incorrect Access Control. | ||
| CVE-2020-7966 | Hig | 0.49 | 7.5 | 0.02 | Feb 5, 2020 | GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal. | ||
| CVE-2019-19629 | Hig | 0.49 | 7.5 | 0.01 | Jan 5, 2020 | In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration. | ||
| CVE-2018-19584 | Hig | 0.49 | 7.5 | 0.02 | Jul 10, 2019 | GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups. | ||
| CVE-2018-19581 | Hig | 0.49 | 7.5 | 0.01 | Jul 10, 2019 | GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create. | ||
| CVE-2019-9220 | Hig | 0.49 | 7.5 | 0.03 | Apr 17, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption. | ||
| CVE-2018-20144 | Hig | 0.49 | 7.5 | 0.02 | Mar 28, 2019 | GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorrect Access Control. | ||
| CVE-2023-5356 | Hig | 0.48 | 7.3 | 0.01 | Jan 12, 2024 | Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as… | ||
| CVE-2023-6680 | Hig | 0.48 | 7.4 | 0.00 | Dec 15, 2023 | An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard… |
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.
- risk 0.49cvss 7.5epss 0.01
Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.
- risk 0.49cvss 7.6epss 0.01
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously…
- risk 0.49cvss 7.5epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads…
- risk 0.49cvss 7.5epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads…
- risk 0.49cvss 7.5epss 0.01
An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects
- risk 0.49cvss 7.5epss 0.01
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.
- risk 0.49cvss 7.5epss 0.02
In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.
- risk 0.49cvss 7.5epss 0.01
GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page.
- risk 0.49cvss 7.5epss 0.01
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
- risk 0.49cvss 7.5epss 0.01
GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.
- risk 0.49cvss 7.5epss 0.01
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
- risk 0.49cvss 7.5epss 0.02
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
- risk 0.49cvss 7.5epss 0.01
In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.
- risk 0.49cvss 7.5epss 0.02
GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups.
- risk 0.49cvss 7.5epss 0.01
GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.
- risk 0.49cvss 7.5epss 0.03
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption.
- risk 0.49cvss 7.5epss 0.02
GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorrect Access Control.
- risk 0.48cvss 7.3epss 0.01
Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as…
- risk 0.48cvss 7.4epss 0.00
An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard…
Page 3 of 15