GitLab EE and CE
by GitLab Inc.
Source repositories
CVEs (583)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-13351 | Med | 0.42 | 6.5 | 0.01 | Nov 17, 2020 | Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2. | ||
| CVE-2020-10977 | Med | 0.42 | 5.5 | 0.43 | Apr 8, 2020 | GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects. | ||
| CVE-2020-10955 | Med | 0.42 | 6.5 | 0.01 | Mar 27, 2020 | GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders. | ||
| CVE-2020-10952 | Med | 0.42 | 6.5 | 0.01 | Mar 27, 2020 | GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images. | ||
| CVE-2018-19583 | Med | 0.42 | 6.5 | 0.02 | Jul 10, 2019 | GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token. | ||
| CVE-2020-13277 | Med | 0.41 | 6.3 | 0.02 | Jun 19, 2020 | An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5 | ||
| CVE-2024-8648 | Med | 0.40 | 6.1 | 0.00 | Nov 14, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL. | ||
| CVE-2022-2417 | Med | 0.40 | 6.2 | 0.01 | Aug 5, 2022 | Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could… | ||
| CVE-2020-13262 | Med | 0.40 | 6.1 | 0.01 | Jun 19, 2020 | Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link | ||
| CVE-2020-13271 | Med | 0.40 | 6.1 | 0.02 | Jun 10, 2020 | A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1 | ||
| CVE-2020-13269 | Med | 0.40 | 6.1 | 0.02 | Jun 10, 2020 | A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1 | ||
| CVE-2020-13267 | Med | 0.40 | 6.1 | 0.02 | Jun 10, 2020 | A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1 | ||
| CVE-2019-15586 | Med | 0.40 | 6.1 | 0.01 | Jan 28, 2020 | A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin. | ||
| CVE-2021-39895 | Med | 0.39 | 6.0 | 0.01 | Nov 5, 2021 | In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project. Under specialized conditions, this may lead to… | ||
| CVE-2026-3160 | Med | 0.38 | 5.8 | 0.00 | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to view Jira issues outside the configured project scope due to an integration filter… | ||
| CVE-2025-2246 | Med | 0.38 | 5.8 | 0.00 | Aug 27, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API. | ||
| CVE-2023-1098 | Med | 0.38 | 5.8 | 0.01 | Apr 5, 2023 | An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from… | ||
| CVE-2022-3613 | Med | 0.38 | 5.8 | 0.01 | Jan 12, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of… | ||
| CVE-2021-39937 | Med | 0.38 | 5.9 | 0.01 | Dec 13, 2021 | A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances | ||
| CVE-2021-39891 | Med | 0.38 | 5.9 | 0.01 | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure. |
- risk 0.42cvss 6.5epss 0.01
Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.
- risk 0.42cvss 5.5epss 0.43
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
- risk 0.42cvss 6.5epss 0.01
GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.
- risk 0.42cvss 6.5epss 0.01
GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.
- risk 0.42cvss 6.5epss 0.02
GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.
- risk 0.41cvss 6.3epss 0.02
An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5
- risk 0.40cvss 6.1epss 0.00
An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL.
- risk 0.40cvss 6.2epss 0.01
Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could…
- risk 0.40cvss 6.1epss 0.01
Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link
- risk 0.40cvss 6.1epss 0.02
A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1
- risk 0.40cvss 6.1epss 0.02
A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1
- risk 0.40cvss 6.1epss 0.02
A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1
- risk 0.40cvss 6.1epss 0.01
A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.
- risk 0.39cvss 6.0epss 0.01
In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project. Under specialized conditions, this may lead to…
- risk 0.38cvss 5.8epss 0.00
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to view Jira issues outside the configured project scope due to an integration filter…
- risk 0.38cvss 5.8epss 0.00
An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.
- risk 0.38cvss 5.8epss 0.01
An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from…
- risk 0.38cvss 5.8epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of…
- risk 0.38cvss 5.9epss 0.01
A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances
- risk 0.38cvss 5.9epss 0.01
In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.
Page 13 of 30