gitlab-org/gitlab-ee
by GitLab Inc.
Source repositories
CVEs (284)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-22167 | Med | 0.35 | 5.3 | 0.02 | Jan 15, 2021 | An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository | ||
| CVE-2020-26406 | Med | 0.35 | 5.3 | 0.01 | Nov 17, 2020 | Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects.… | ||
| CVE-2020-15525 | Med | 0.35 | 5.3 | 0.01 | Jul 7, 2020 | GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint. | ||
| CVE-2020-12448 | Med | 0.35 | 5.3 | 0.01 | May 7, 2020 | GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet. | ||
| CVE-2020-10084 | Med | 0.35 | 5.3 | 0.01 | Mar 13, 2020 | GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace | ||
| CVE-2020-7977 | Med | 0.35 | 5.3 | 0.01 | Feb 5, 2020 | GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions. | ||
| CVE-2020-7976 | Med | 0.35 | 5.3 | 0.01 | Feb 5, 2020 | GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control. | ||
| CVE-2020-7974 | Med | 0.35 | 5.3 | 0.01 | Feb 5, 2020 | GitLab EE 10.1 through 12.7.2 allows Information Disclosure. | ||
| CVE-2020-7979 | Med | 0.35 | 5.3 | 0.01 | Feb 5, 2020 | GitLab EE 8.9 and later through 12.7.2 has Insecure Permission | ||
| CVE-2019-5487 | Med | 0.35 | 5.3 | 0.01 | Dec 18, 2019 | An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits. | ||
| CVE-2019-15721 | Med | 0.35 | 5.4 | 0.01 | Sep 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintentionally allowed group maintainers to view and edit group runner settings. | ||
| CVE-2019-6995 | Med | 0.35 | 6.5 | 0.01 | Sep 9, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues. | ||
| CVE-2018-19579 | Med | 0.35 | 5.4 | 0.01 | Jul 10, 2019 | GitLab EE version 11.5 is vulnerable to a persistent XSS vulnerability in the Operations page. This is fixed in 11.5.1. | ||
| CVE-2018-17975 | Med | 0.35 | 5.3 | 0.01 | Dec 4, 2018 | An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the GFM markdown API. | ||
| CVE-2024-9512 | Med | 0.34 | 5.3 | 0.00 | Jun 12, 2025 | An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync. | ||
| CVE-2024-10925 | Med | 0.34 | 5.3 | 0.00 | Mar 3, 2025 | A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to read Security policy YAML | ||
| CVE-2024-8650 | Med | 0.34 | 5.3 | 0.00 | Dec 16, 2024 | An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests. | ||
| CVE-2024-10240 | Med | 0.34 | 5.3 | 0.01 | Nov 26, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a… | ||
| CVE-2024-2191 | Med | 0.34 | 5.3 | 0.00 | Jun 27, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only. | ||
| CVE-2023-3102 | Med | 0.34 | 5.3 | 0.01 | Jul 21, 2023 | A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR. |
- risk 0.35cvss 5.3epss 0.02
An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository
- risk 0.35cvss 5.3epss 0.01
Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects.…
- risk 0.35cvss 5.3epss 0.01
GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.
- risk 0.35cvss 5.3epss 0.01
GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.
- risk 0.35cvss 5.3epss 0.01
GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace
- risk 0.35cvss 5.3epss 0.01
GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.
- risk 0.35cvss 5.3epss 0.01
GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.
- risk 0.35cvss 5.3epss 0.01
GitLab EE 10.1 through 12.7.2 allows Information Disclosure.
- risk 0.35cvss 5.3epss 0.01
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
- risk 0.35cvss 5.3epss 0.01
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintentionally allowed group maintainers to view and edit group runner settings.
- risk 0.35cvss 6.5epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.
- risk 0.35cvss 5.4epss 0.01
GitLab EE version 11.5 is vulnerable to a persistent XSS vulnerability in the Operations page. This is fixed in 11.5.1.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the GFM markdown API.
- risk 0.34cvss 5.3epss 0.00
An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.
- risk 0.34cvss 5.3epss 0.00
A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to read Security policy YAML
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.
- risk 0.34cvss 5.3epss 0.01
An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a…
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.
- risk 0.34cvss 5.3epss 0.01
A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR.
Page 7 of 15