VYPR

GitLab EE and CE

by GitLab Inc.

Source repositories

CVEs (607)

  • CVE-2021-39894MedOct 5, 2021
    risk 0.35cvss 5.4epss 0.01

    In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

  • CVE-2021-39875MedOct 5, 2021
    risk 0.35cvss 5.3epss 0.01

    In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.

  • CVE-2021-22256MedAug 25, 2021
    risk 0.35cvss 5.4epss 0.01

    Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

  • CVE-2021-22250MedAug 25, 2021
    risk 0.35cvss 5.4epss 0.01

    Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account

  • CVE-2021-22248MedAug 23, 2021
    risk 0.35cvss 5.3epss 0.01

    Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only

  • CVE-2021-22210MedMay 6, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.

  • CVE-2020-26408MedDec 11, 2020
    risk 0.35cvss 5.3epss 0.01

    A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile

  • CVE-2020-13264MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token

  • CVE-2020-13261MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code

  • CVE-2020-13268MedJun 10, 2020
    risk 0.35cvss 5.3epss 0.01

    A specially crafted request could be used to confirm the existence of files hosted on object storage services, without disclosing their contents. This vulnerability affects GitLab CE/EE 12.10 and later through 13.0.1

  • CVE-2020-10978MedApr 8, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.

  • CVE-2019-5467MedSep 9, 2019
    risk 0.35cvss 5.4epss 0.01

    An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result in a persistent XSS. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

  • CVE-2019-5463MedSep 9, 2019
    risk 0.35cvss 5.3epss 0.02

    An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

  • CVE-2018-19574MedJul 10, 2019
    risk 0.35cvss 5.4epss 0.01

    GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in the OAuth authorization page.

  • CVE-2018-19573MedJul 10, 2019
    risk 0.35cvss 5.4epss 0.01

    GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via Mermaid.

  • CVE-2018-19570MedJul 10, 2019
    risk 0.35cvss 5.4epss 0.01

    GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

  • CVE-2018-19577MedJul 10, 2019
    risk 0.35cvss 5.3epss 0.02

    Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.

  • CVE-2026-82837MedSep 15, 2026
    risk 0.34cvss 5.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials and tokens without transiting the expected…

  • CVE-2026-7427MedAug 12, 2026
    risk 0.34cvss 5.3epss 0.01

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to improper input validation.

  • CVE-2026-7492MedJul 8, 2026
    risk 0.34cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper…

Page 17 of 31