VYPR

gitlab-org/gitlab-ee

by GitLab Inc.

Source repositories

CVEs (297)

  • CVE-2019-19313HigJan 5, 2020
    risk 0.42cvss 7.5epss 0.01

    GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.

  • CVE-2018-19578MedJul 10, 2019
    risk 0.42cvss 6.5epss 0.01

    GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the Jaeger Tracing Operations page.

  • CVE-2024-11129MedApr 10, 2025
    risk 0.41cvss 6.3epss 0.00

    An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted searches with sensitive keywords to get the count of issues containing the searched term."

  • CVE-2022-2417MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.01

    Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could…

  • CVE-2018-19493MedJul 10, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding.

  • CVE-2023-5612MedJan 26, 2024
    risk 0.38cvss 5.3epss 0.05

    An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

  • CVE-2023-5332MedDec 4, 2023
    risk 0.38cvss 5.9epss 0.01

    Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

  • CVE-2023-2589MedJun 7, 2023
    risk 0.38cvss 5.9epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker can clone a repository from a public project, from a disallowed IP,…

  • CVE-2023-1098MedApr 5, 2023
    risk 0.38cvss 5.8epss 0.01

    An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from…

  • CVE-2022-2501MedAug 5, 2022
    risk 0.38cvss 5.9epss 0.01

    An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an attacker to bypass IP allow-listing and download artifacts. This attack only bypasses IP allow-listing, proper permissions are…

  • CVE-2021-22200MedApr 2, 2021
    risk 0.38cvss 5.9epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an internal repository through a public project fork as an anonymous user.

  • CVE-2026-1516MedApr 8, 2026
    risk 0.37cvss 5.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of users viewing the report via specially crafted…

  • CVE-2024-4597MedMay 14, 2024
    risk 0.37cvss 5.7epss 0.00

    An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.

  • CVE-2022-4331MedMar 9, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group,…

  • CVE-2020-13348MedNov 17, 2020
    risk 0.37cvss 5.7epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

  • CVE-2026-3035MedAug 26, 2026
    risk 0.36cvss 5.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with project Maintainer permissions could have accessed the terminal of a protected…

  • CVE-2024-4278MedSep 26, 2024
    risk 0.36cvss 5.5epss 0.00

    An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy…

  • CVE-2023-4378MedSep 1, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A malicious Maintainer can, under specific circumstances, leak the sentry token by…

  • CVE-2023-3950MedSep 1, 2023
    risk 0.36cvss 5.5epss 0.00

    An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the…

  • CVE-2026-4398MedApr 8, 2026
    risk 0.35cvss 5.4epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from namespaces they were not authorized to…

Page 6 of 15