VYPR

GitLab EE and CE

by GitLab Inc.

Source repositories

CVEs (607)

  • CVE-2025-5101MedAug 27, 2025
    risk 0.33cvss 5.0epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by…

  • CVE-2025-5819MedAug 13, 2025
    risk 0.33cvss 5.0epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users with developer access to obtain ID tokens for protected branches under certain circumstances.

  • CVE-2022-2243MedJul 1, 2022
    risk 0.33cvss 5.0epss 0.01

    An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.

  • CVE-2021-22239MedSep 9, 2021
    risk 0.33cvss 5.0epss 0.01

    An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.

  • CVE-2025-4979MedMay 22, 2025
    risk 0.32cvss 4.9epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and…

  • CVE-2024-9623MedOct 10, 2024
    risk 0.32cvss 4.9epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows deploy keys to push to an archived repository.

  • CVE-2024-7554MedAug 8, 2024
    risk 0.32cvss 4.9epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request…

  • CVE-2024-5257MedJul 11, 2024
    risk 0.32cvss 4.9epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

  • CVE-2022-2456MedAug 5, 2022
    risk 0.32cvss 4.9epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for malicious group or project maintainers to change their corresponding group or…

  • CVE-2021-22186MedMar 24, 2021
    risk 0.32cvss 4.9epss 0.01

    An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners

  • CVE-2026-19619MedSep 16, 2026
    risk 0.31cvss 4.7epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in the context of a targeted user's…

  • CVE-2023-3500MedAug 2, 2023
    risk 0.31cvss 4.8epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed…

  • CVE-2022-3726MedNov 10, 2022
    risk 0.31cvss 4.8epss 0.01

    Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's…

  • CVE-2022-3486MedNov 9, 2022
    risk 0.31cvss 4.7epss 0.01

    An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.

  • CVE-2022-2250MedJul 1, 2022
    risk 0.31cvss 4.7epss 0.02

    An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.

  • CVE-2022-1120MedApr 4, 2022
    risk 0.31cvss 4.8epss 0.01

    Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

  • CVE-2022-0741MedApr 1, 2022
    risk 0.31cvss 5.8epss 0.01

    Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables via specially crafted email addresses.

  • CVE-2020-13358MedNov 17, 2020
    risk 0.31cvss 4.7epss 0.00

    A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

  • CVE-2026-1094MedFeb 11, 2026
    risk 0.30cvss 4.6epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an authenticated developer to hide specially crafted file changes from the WebUI.

  • CVE-2025-0605MedMay 22, 2025
    risk 0.30cvss 4.6epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

Page 19 of 31