VYPR

GitLab

by GitLab Inc.

Source repositories

CVEs (1,462)

  • CVE-2022-4092MedJan 26, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input.

  • CVE-2022-2907MedJan 17, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It was possible to read repository content by an unauthorised user if a project…

  • CVE-2021-22194MedMar 26, 2021
    risk 0.37cvss 5.7epss 0.00

    In all versions of GitLab, marshalled session keys were being stored in Redis.

  • CVE-2020-26413MedDec 11, 2020
    risk 0.37cvss 5.3epss 0.35

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

  • CVE-2020-13348MedNov 17, 2020
    risk 0.37cvss 5.7epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

  • CVE-2020-13344MedOct 8, 2020
    risk 0.37cvss 5.7epss 0.00

    An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are stored in plain-text in Redis which allows attacker with Redis access to authenticate as any user that has a session stored in Redis

  • CVE-2026-3035MedAug 26, 2026
    risk 0.36cvss 5.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with project Maintainer permissions could have accessed the terminal of a protected…

  • CVE-2024-4278MedSep 26, 2024
    risk 0.36cvss 5.5epss 0.00

    An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy…

  • CVE-2023-4378MedSep 1, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A malicious Maintainer can, under specific circumstances, leak the sentry token by…

  • CVE-2023-3950MedSep 1, 2023
    risk 0.36cvss 5.5epss 0.00

    An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the…

  • CVE-2023-2620MedJul 13, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other…

  • CVE-2023-0838MedApr 5, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix…

  • CVE-2023-0483MedMar 9, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by…

  • CVE-2022-4054MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to leak a webhook secret token by changing the…

  • CVE-2022-3902MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to unmask webhook secret tokens by reviewing the…

  • CVE-2022-4365MedJan 12, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by changing the configured URL in…

  • CVE-2022-4342MedJan 12, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of…

  • CVE-2022-3483MedNov 9, 2022
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could exfiltrate a Datadog integration's access token by…

  • CVE-2022-2882MedOct 28, 2022
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by…

  • CVE-2021-22263MedOct 11, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project…

Page 34 of 74