VYPR

GitLab EE and CE

by GitLab Inc.

Source repositories

CVEs (583)

  • CVE-2026-4916LowApr 8, 2026
    risk 0.18cvss 2.7epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to…

  • CVE-2025-1110LowMay 22, 2025
    risk 0.18cvss 2.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.

  • CVE-2024-0231LowJul 24, 2024
    risk 0.18cvss 2.7epss 0.00

    A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits.

  • CVE-2024-2880LowJul 11, 2024
    risk 0.18cvss 2.7epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members.

  • CVE-2023-1084LowMar 9, 2023
    risk 0.18cvss 2.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a…

  • CVE-2022-3325LowOct 17, 2022
    risk 0.18cvss 2.7epss 0.00

    Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.

  • CVE-2022-3279LowOct 17, 2022
    risk 0.18cvss 2.7epss 0.01

    An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs

  • CVE-2022-1783LowJun 6, 2022
    risk 0.18cvss 2.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for malicious group maintainers to add new members to a…

  • CVE-2021-39945LowDec 13, 2021
    risk 0.18cvss 2.7epss 0.01

    Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after…

  • CVE-2021-39901LowNov 5, 2021
    risk 0.18cvss 2.7epss 0.01

    In all versions of GitLab CE/EE since version 11.10, an admin of a group can see the SCIM token of that group by visiting a specific endpoint.

  • CVE-2021-22245LowAug 25, 2021
    risk 0.18cvss 2.7epss 0.01

    Improper validation of commit author in GitLab CE/EE affecting all versions allowed an attacker to make several pages in a project impossible to view

  • CVE-2023-6195LowJan 31, 2025
    risk 0.17cvss 2.6epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in…

  • CVE-2024-8974LowSep 26, 2024
    risk 0.17cvss 2.6epss 0.00

    Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."

  • CVE-2024-7060LowJul 24, 2024
    risk 0.17cvss 2.6epss 0.00

    An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.

  • CVE-2023-2013LowJun 7, 2023
    risk 0.17cvss 2.6epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An issue was found that allows someone to abuse a discrepancy between the Web…

  • CVE-2022-1157LowApr 11, 2022
    risk 0.17cvss 2.6epss 0.01

    Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

  • CVE-2022-1188LowApr 4, 2022
    risk 0.17cvss 3.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.

  • CVE-2021-39910LowDec 13, 2021
    risk 0.17cvss 2.6epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.

  • CVE-2021-39897LowNov 5, 2021
    risk 0.17cvss 2.6epss 0.01

    Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the subgroup is transferred

  • CVE-2022-1111LowApr 4, 2022
    risk 0.16cvss 2.4epss 0.01

    A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages