GitLab
by GitLab Inc.
Source repositories
CVEs (1,455)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-13318 | Med | 0.42 | 6.4 | 0.01 | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack. | ||
| CVE-2020-13284 | Med | 0.42 | 6.5 | 0.01 | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token | ||
| CVE-2020-13286 | Med | 0.42 | 6.4 | 0.01 | Aug 13, 2020 | For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery. | ||
| CVE-2020-13281 | Med | 0.42 | 6.5 | 0.01 | Aug 13, 2020 | For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature | ||
| CVE-2020-13280 | Med | 0.42 | 6.5 | 0.01 | Aug 13, 2020 | For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message. | ||
| CVE-2020-11649 | Med | 0.42 | 6.5 | 0.01 | Apr 22, 2020 | An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted. | ||
| CVE-2020-10977 | Med | 0.42 | 5.5 | 0.43 | Apr 8, 2020 | GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects. | ||
| CVE-2020-10955 | Med | 0.42 | 6.5 | 0.01 | Mar 27, 2020 | GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders. | ||
| CVE-2020-10952 | Med | 0.42 | 6.5 | 0.01 | Mar 27, 2020 | GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images. | ||
| CVE-2020-10081 | Med | 0.42 | 6.5 | 0.01 | Mar 13, 2020 | GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user. | ||
| CVE-2019-13009 | Med | 0.42 | 6.5 | 0.01 | Mar 10, 2020 | An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It has Incorrect Access Control. | ||
| CVE-2019-12429 | Med | 0.42 | 6.5 | 0.01 | Mar 10, 2020 | An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control. | ||
| CVE-2013-4582 | Med | 0.42 | 6.5 | 0.02 | Jan 28, 2020 | The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to… | ||
| CVE-2019-5474 | Med | 0.42 | 6.5 | 0.01 | Jan 28, 2020 | An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions. | ||
| CVE-2019-19314 | Hig | 0.42 | 7.5 | 0.01 | Jan 5, 2020 | GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext. | ||
| CVE-2019-19313 | Hig | 0.42 | 7.5 | 0.01 | Jan 5, 2020 | GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits. | ||
| CVE-2019-15584 | Med | 0.42 | 6.5 | 0.01 | Dec 20, 2019 | A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page. | ||
| CVE-2019-5469 | Med | 0.42 | 6.5 | 0.01 | Dec 18, 2019 | An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets. | ||
| CVE-2019-15591 | Med | 0.42 | 6.5 | 0.01 | Dec 18, 2019 | An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled. | ||
| CVE-2019-15580 | Med | 0.42 | 6.5 | 0.01 | Dec 18, 2019 | An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was… |
- risk 0.42cvss 6.4epss 0.01
A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.
- risk 0.42cvss 6.5epss 0.01
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token
- risk 0.42cvss 6.4epss 0.01
For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.
- risk 0.42cvss 6.5epss 0.01
For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature
- risk 0.42cvss 6.5epss 0.01
For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.
- risk 0.42cvss 5.5epss 0.43
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
- risk 0.42cvss 6.5epss 0.01
GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.
- risk 0.42cvss 6.5epss 0.01
GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.
- risk 0.42cvss 6.5epss 0.01
GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It has Incorrect Access Control.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.
- risk 0.42cvss 6.5epss 0.02
The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to…
- risk 0.42cvss 6.5epss 0.01
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.
- risk 0.42cvss 7.5epss 0.01
GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.
- risk 0.42cvss 7.5epss 0.01
GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.
- risk 0.42cvss 6.5epss 0.01
A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.
- risk 0.42cvss 6.5epss 0.01
An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.
- risk 0.42cvss 6.5epss 0.01
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
- risk 0.42cvss 6.5epss 0.01
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was…
Page 27 of 73