VYPR

GitLab::API::v4

by GitLab Inc.

Source repositories

CVEs (2)

  • CVE-2022-0549MedMar 28, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under certain conditions, GitLab REST API may allow unprivileged users to add other users to groups…

  • CVE-2023-31485MedApr 29, 2023
    risk 0.00cvss 5.9epss 0.01

    GitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-the-middle attacks.