GitLab
by GitLab Inc.
Source repositories
CVEs (1,455)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0090 | Med | 0.42 | 6.5 | 0.01 | Jan 18, 2022 | An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of… | ||
| CVE-2021-39939 | Med | 0.42 | 6.5 | 0.01 | Dec 13, 2021 | An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted… | ||
| CVE-2021-39903 | Med | 0.42 | 6.5 | 0.01 | Nov 4, 2021 | In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings. | ||
| CVE-2021-39872 | Med | 0.42 | 6.5 | 0.01 | Oct 5, 2021 | In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration. | ||
| CVE-2021-39869 | Med | 0.42 | 6.5 | 0.01 | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project. | ||
| CVE-2021-39867 | Med | 0.42 | 6.5 | 0.01 | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks. | ||
| CVE-2021-22252 | Med | 0.42 | 6.5 | 0.01 | Aug 23, 2021 | A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to Maintainers | ||
| CVE-2021-22228 | Med | 0.42 | 6.5 | 0.01 | Jul 6, 2021 | An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2. Improper access control allows unauthorised users to access project details using Graphql. | ||
| CVE-2021-22226 | Med | 0.42 | 6.5 | 0.01 | Jul 6, 2021 | Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9 | ||
| CVE-2021-22216 | Med | 0.42 | 6.5 | 0.01 | Jun 8, 2021 | A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description | ||
| CVE-2021-22221 | Med | 0.42 | 6.5 | 0.01 | Jun 8, 2021 | An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to… | ||
| CVE-2021-22217 | Med | 0.42 | 6.5 | 0.02 | Jun 8, 2021 | A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request | ||
| CVE-2020-13351 | Med | 0.42 | 6.5 | 0.01 | Nov 17, 2020 | Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2. | ||
| CVE-2020-13346 | Med | 0.42 | 6.5 | 0.01 | Oct 7, 2020 | Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API. | ||
| CVE-2020-13329 | Med | 0.42 | 6.5 | 0.01 | Sep 30, 2020 | An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the blob view feature. | ||
| CVE-2020-13324 | Med | 0.42 | 6.5 | 0.01 | Sep 30, 2020 | A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API. | ||
| CVE-2020-13320 | Med | 0.42 | 6.5 | 0.01 | Sep 30, 2020 | An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard. | ||
| CVE-2020-13296 | Med | 0.42 | 6.5 | 0.02 | Sep 30, 2020 | An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens | ||
| CVE-2020-13310 | Med | 0.42 | 6.5 | 0.02 | Sep 14, 2020 | A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the gitlab-runner process crash by sending malformed queries, resulting in a denial of service. | ||
| CVE-2020-13312 | Med | 0.42 | 6.5 | 0.01 | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter. |
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of…
- risk 0.42cvss 6.5epss 0.01
An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted…
- risk 0.42cvss 6.5epss 0.01
In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings.
- risk 0.42cvss 6.5epss 0.01
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
- risk 0.42cvss 6.5epss 0.01
In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
- risk 0.42cvss 6.5epss 0.01
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
- risk 0.42cvss 6.5epss 0.01
A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to Maintainers
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2. Improper access control allows unauthorised users to access project details using Graphql.
- risk 0.42cvss 6.5epss 0.01
Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9
- risk 0.42cvss 6.5epss 0.01
A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to…
- risk 0.42cvss 6.5epss 0.02
A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request
- risk 0.42cvss 6.5epss 0.01
Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.
- risk 0.42cvss 6.5epss 0.01
Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the blob view feature.
- risk 0.42cvss 6.5epss 0.01
A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard.
- risk 0.42cvss 6.5epss 0.02
An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens
- risk 0.42cvss 6.5epss 0.02
A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the gitlab-runner process crash by sending malformed queries, resulting in a denial of service.
- risk 0.42cvss 6.5epss 0.01
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.
Page 26 of 73