VYPR

gitlab-org/gitlab-ee

by GitLab Inc.

Source repositories

CVEs (284)

  • CVE-2023-5933MedJan 26, 2024
    risk 0.42cvss 6.4epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

  • CVE-2023-5825MedNov 6, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can point a CI/CD Component to an incorrect path and…

  • CVE-2023-3413MedSep 29, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before…

  • CVE-2023-3915MedSep 1, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may…

  • CVE-2023-1621MedJun 6, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to commit to projects even from a restricted IP address.

  • CVE-2022-3291MedOct 17, 2022
    risk 0.42cvss 6.5epss 0.01

    Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache

  • CVE-2022-2498MedAug 5, 2022
    risk 0.42cvss 6.4epss 0.01

    An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.

  • CVE-2022-1983MedJul 1, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any location to access Container Registries…

  • CVE-2022-1936MedJun 6, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any…

  • CVE-2022-1935MedJun 6, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any…

  • CVE-2020-13351MedNov 17, 2020
    risk 0.42cvss 6.5epss 0.01

    Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.

  • CVE-2020-13281MedAug 13, 2020
    risk 0.42cvss 6.5epss 0.01

    For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature

  • CVE-2019-5474MedJan 28, 2020
    risk 0.42cvss 6.5epss 0.01

    An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.

  • CVE-2019-19314HigJan 5, 2020
    risk 0.42cvss 7.5epss 0.01

    GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.

  • CVE-2019-19313HigJan 5, 2020
    risk 0.42cvss 7.5epss 0.01

    GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.

  • CVE-2018-19578MedJul 10, 2019
    risk 0.42cvss 6.5epss 0.01

    GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the Jaeger Tracing Operations page.

  • CVE-2024-11129MedApr 10, 2025
    risk 0.41cvss 6.3epss 0.00

    An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted searches with sensitive keywords to get the count of issues containing the searched term."

  • CVE-2022-2417MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.01

    Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could…

  • CVE-2018-19493MedJul 10, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding.

  • CVE-2023-5612MedJan 26, 2024
    risk 0.38cvss 5.3epss 0.05

    An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

Page 5 of 15