VYPR

GitLab EE and CE

by GitLab Inc.

Source repositories

CVEs (599)

  • CVE-2020-26409MedDec 11, 2020
    risk 0.28cvss 4.3epss 0.01

    A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

  • CVE-2020-13354MedNov 17, 2020
    risk 0.28cvss 4.3epss 0.01

    A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9.

  • CVE-2020-13265MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

  • CVE-2020-13266MedJun 9, 2020
    risk 0.28cvss 4.3epss 0.01

    Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions

  • CVE-2020-10981MedApr 8, 2020
    risk 0.28cvss 4.3epss 0.01

    GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeline trigger descriptions within the same project.

  • CVE-2020-10979MedApr 8, 2020
    risk 0.28cvss 4.3epss 0.01

    GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users.

  • CVE-2020-10975MedApr 8, 2020
    risk 0.28cvss 4.3epss 0.01

    GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments on vulnerabilities to unauthorized users on the vulnerability feedback page.

  • CVE-2019-5466MedJan 28, 2020
    risk 0.28cvss 4.3epss 0.01

    An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.

  • CVE-2019-5465MedJan 28, 2020
    risk 0.28cvss 4.3epss 0.01

    An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.

  • CVE-2019-15577MedDec 18, 2019
    risk 0.28cvss 4.3epss 0.01

    An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.

  • CVE-2018-19575MedJul 10, 2019
    risk 0.28cvss 4.3epss 0.01

    GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue.

  • CVE-2026-1230MedMar 11, 2026
    risk 0.27cvss 4.1epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause repository downloads to contain different code than displayed in the web interface due…

  • CVE-2025-1198MedFeb 13, 2025
    risk 0.27cvss 4.2epss 0.00

    An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCable potentially allowed revoked Personal Access Tokens access to streaming results.

  • CVE-2024-13041MedJan 9, 2025
    risk 0.27cvss 4.2epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external…

  • CVE-2024-11668MedNov 26, 2024
    risk 0.27cvss 4.2epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially bypass authentication controls, allowing unauthorized access to streaming results.

  • CVE-2024-3958MedAug 8, 2024
    risk 0.27cvss 5.3epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social…

  • CVE-2024-7091MedJul 24, 2024
    risk 0.27cvss 4.1epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.

  • CVE-2023-2200MedJul 13, 2023
    risk 0.27cvss 4.1epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML in an email address field.

  • CVE-2024-12292MedDec 12, 2024
    risk 0.26cvss 4.0epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.

  • CVE-2024-5318MedMay 24, 2024
    risk 0.26cvss 4.0epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from 16.11 prior to 16.11.3, and starting from 17.0 prior to 17.0.1. A Guest user can view dependency lists of private projects through job artifacts.

Page 25 of 30