VYPR

GitLab EE and CE

by GitLab Inc.

Source repositories

CVEs (585)

  • CVE-2023-2198HigJun 7, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads…

  • CVE-2023-2132HigJun 6, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A DollarMathPostFilter Regular Expression Denial of Service in was possible by…

  • CVE-2022-3283HigOct 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 While cloning an issue with special crafted content added to the description…

  • CVE-2022-2931HigOct 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high…

  • CVE-2022-2229HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects…

  • CVE-2021-22209HigMay 6, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.

  • CVE-2021-22203HigApr 2, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7.9 before 13.8.7, all versions starting from 13.9 before 13.9.5, and all versions starting from 13.10 before 13.10.1. A specially crafted Wiki page allowed attackers to read arbitrary files on…

  • CVE-2020-13359HigNov 19, 2020
    risk 0.49cvss 7.6epss 0.01

    The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4,…

  • CVE-2020-13355HigNov 19, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server. Affected versions are: >=8.14, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

  • CVE-2020-13273HigJun 19, 2020
    risk 0.49cvss 7.5epss 0.01

    A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1

  • CVE-2020-13270HigJun 10, 2020
    risk 0.49cvss 7.5epss 0.01

    Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API

  • CVE-2020-10976HigApr 8, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget.

  • CVE-2019-15576HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.02

    An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

  • CVE-2019-15575HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.02

    A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

  • CVE-2018-19856HigMar 26, 2019
    risk 0.49cvss 7.5epss 0.02

    GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API.

  • CVE-2026-0723HigJan 22, 2026
    risk 0.48cvss 7.4epss 0.01

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an individual with existing knowledge of a victim's credential ID to bypass two-factor authentication by submitting…

  • CVE-2022-2904HigNov 2, 2022
    risk 0.48cvss 7.3epss 0.01

    A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 It was possible to exploit a vulnerability in the external…

  • CVE-2022-3060HigOct 17, 2022
    risk 0.48cvss 7.3epss 0.01

    Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests

  • CVE-2022-2865HigOct 17, 2022
    risk 0.48cvss 7.3epss 0.01

    A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers…

  • CVE-2022-2527HigOct 17, 2022
    risk 0.48cvss 7.3epss 0.01

    An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary…

Page 7 of 30