VYPR

GitLab

by GitLab Inc.

Source repositories

CVEs (1,462)

  • CVE-2017-0882MedMar 28, 2017
    risk 0.41cvss 6.3epss 0.01

    Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

  • CVE-2024-8648MedNov 14, 2024
    risk 0.40cvss 6.1epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL.

  • CVE-2023-2164MedAug 2, 2023
    risk 0.40cvss 5.4epss 0.64

    An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user…

  • CVE-2022-3513MedApr 5, 2023
    risk 0.40cvss 6.1epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A specially crafted payload could lead to a reflected XSS on the client side which…

  • CVE-2023-0042MedJan 12, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.

  • CVE-2022-2417MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.01

    Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could…

  • CVE-2022-1460MedMay 11, 2022
    risk 0.40cvss 6.1epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a…

  • CVE-2021-22170MedDec 6, 2021
    risk 0.40cvss 6.2epss 0.01

    Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content

  • CVE-2021-22227MedJul 7, 2021
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it

  • CVE-2021-22223MedJul 6, 2021
    risk 0.40cvss 6.1epss 0.01

    Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

  • CVE-2021-22220MedJun 8, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

  • CVE-2021-22184MedMar 26, 2021
    risk 0.40cvss 6.2epss 0.00

    An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.

  • CVE-2020-13262MedJun 19, 2020
    risk 0.40cvss 6.1epss 0.01

    Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link

  • CVE-2020-13271MedJun 10, 2020
    risk 0.40cvss 6.1epss 0.02

    A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1

  • CVE-2020-13269MedJun 10, 2020
    risk 0.40cvss 6.1epss 0.02

    A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1

  • CVE-2020-13267MedJun 10, 2020
    risk 0.40cvss 6.1epss 0.02

    A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1

  • CVE-2020-10076MedMar 13, 2020
    risk 0.40cvss 6.1epss 0.01

    GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge requests.

  • CVE-2020-10075MedMar 13, 2020
    risk 0.40cvss 6.1epss 0.01

    GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or potentially other vulnerabilities via unescaped input.

  • CVE-2020-10092MedMar 13, 2020
    risk 0.40cvss 6.1epss 0.01

    GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.

  • CVE-2020-10091MedMar 13, 2020
    risk 0.40cvss 6.1epss 0.01

    GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.

Page 30 of 74