gitlab-org/gitlab-ee
by GitLab Inc.
Source repositories
CVEs (284)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-2198 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads… | ||
| CVE-2021-22215 | Hig | 0.49 | 7.5 | 0.01 | Jun 8, 2021 | An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects | ||
| CVE-2020-13263 | Hig | 0.49 | 7.5 | 0.01 | Jun 19, 2020 | An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions. | ||
| CVE-2020-10953 | Hig | 0.49 | 7.5 | 0.01 | Mar 27, 2020 | In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue. | ||
| CVE-2020-10073 | Hig | 0.49 | 7.5 | 0.01 | Mar 13, 2020 | GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page. | ||
| CVE-2020-7972 | Hig | 0.49 | 7.5 | 0.01 | Feb 5, 2020 | GitLab EE 12.2 has Insecure Permissions (issue 2 of 2). | ||
| CVE-2020-7969 | Hig | 0.49 | 7.5 | 0.01 | Feb 5, 2020 | GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure. | ||
| CVE-2020-7968 | Hig | 0.49 | 7.5 | 0.01 | Feb 5, 2020 | GitLab EE 8.0 through 12.7.2 has Incorrect Access Control. | ||
| CVE-2020-7966 | Hig | 0.49 | 7.5 | 0.02 | Feb 5, 2020 | GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal. | ||
| CVE-2019-19629 | Hig | 0.49 | 7.5 | 0.01 | Jan 5, 2020 | In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration. | ||
| CVE-2018-19584 | Hig | 0.49 | 7.5 | 0.02 | Jul 10, 2019 | GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups. | ||
| CVE-2018-19581 | Hig | 0.49 | 7.5 | 0.01 | Jul 10, 2019 | GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create. | ||
| CVE-2019-9220 | Hig | 0.49 | 7.5 | 0.03 | Apr 17, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption. | ||
| CVE-2018-20144 | Hig | 0.49 | 7.5 | 0.02 | Mar 28, 2019 | GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorrect Access Control. | ||
| CVE-2023-5356 | Hig | 0.48 | 7.3 | 0.01 | Jan 12, 2024 | Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as… | ||
| CVE-2023-6680 | Hig | 0.48 | 7.4 | 0.00 | Dec 15, 2023 | An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard… | ||
| CVE-2017-0925 | Hig | 0.47 | 7.2 | 0.01 | Mar 21, 2018 | Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password. | ||
| CVE-2026-16494 | Hig | 0.46 | 7.1 | 0.00 | Aug 12, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization… | ||
| CVE-2023-4379 | Hig | 0.46 | 8.1 | 0.01 | Nov 9, 2023 | An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated. | ||
| CVE-2022-1423 | Hig | 0.46 | 7.1 | 0.01 | May 19, 2022 | Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache… |
- risk 0.49cvss 7.5epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads…
- risk 0.49cvss 7.5epss 0.01
An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects
- risk 0.49cvss 7.5epss 0.01
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.
- risk 0.49cvss 7.5epss 0.01
In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.
- risk 0.49cvss 7.5epss 0.01
GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page.
- risk 0.49cvss 7.5epss 0.01
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
- risk 0.49cvss 7.5epss 0.01
GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.
- risk 0.49cvss 7.5epss 0.01
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
- risk 0.49cvss 7.5epss 0.02
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
- risk 0.49cvss 7.5epss 0.01
In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.
- risk 0.49cvss 7.5epss 0.02
GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups.
- risk 0.49cvss 7.5epss 0.01
GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.
- risk 0.49cvss 7.5epss 0.03
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption.
- risk 0.49cvss 7.5epss 0.02
GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorrect Access Control.
- risk 0.48cvss 7.3epss 0.01
Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as…
- risk 0.48cvss 7.4epss 0.00
An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard…
- risk 0.47cvss 7.2epss 0.01
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
- risk 0.46cvss 7.1epss 0.00
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization…
- risk 0.46cvss 8.1epss 0.01
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.
- risk 0.46cvss 7.1epss 0.01
Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache…
Page 3 of 15