GitLab
by GitLab Inc.
Source repositories
CVEs (1,462)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-39912 | Med | 0.35 | 5.3 | 0.01 | Nov 5, 2021 | A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion. | ||
| CVE-2021-39907 | Med | 0.35 | 5.3 | 0.01 | Nov 5, 2021 | A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage. | ||
| CVE-2021-39880 | Med | 0.35 | 6.5 | 0.02 | Oct 5, 2021 | A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users… | ||
| CVE-2021-22262 | Med | 0.35 | 5.4 | 0.01 | Oct 5, 2021 | Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and… | ||
| CVE-2021-22257 | Med | 0.35 | 5.3 | 0.01 | Oct 5, 2021 | An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled.… | ||
| CVE-2021-39894 | Med | 0.35 | 5.4 | 0.01 | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks. | ||
| CVE-2021-39893 | Med | 0.35 | 5.3 | 0.01 | Oct 5, 2021 | A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation. | ||
| CVE-2021-39875 | Med | 0.35 | 5.3 | 0.01 | Oct 5, 2021 | In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint. | ||
| CVE-2021-39866 | Med | 0.35 | 5.4 | 0.01 | Oct 5, 2021 | A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens. | ||
| CVE-2021-22256 | Med | 0.35 | 5.4 | 0.01 | Aug 25, 2021 | Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status | ||
| CVE-2021-22250 | Med | 0.35 | 5.4 | 0.01 | Aug 25, 2021 | Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account | ||
| CVE-2021-22248 | Med | 0.35 | 5.3 | 0.01 | Aug 23, 2021 | Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only | ||
| CVE-2021-22210 | Med | 0.35 | 5.3 | 0.01 | May 6, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results. | ||
| CVE-2021-22185 | Med | 0.35 | 5.4 | 0.01 | Mar 24, 2021 | Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted commit to a wiki | ||
| CVE-2021-22179 | Med | 0.35 | 5.4 | 0.01 | Mar 24, 2021 | A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature. | ||
| CVE-2021-22188 | Med | 0.35 | 5.3 | 0.01 | Mar 3, 2021 | An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorised user via branch logs. | ||
| CVE-2021-22167 | Med | 0.35 | 5.3 | 0.02 | Jan 15, 2021 | An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository | ||
| CVE-2021-22166 | Med | 0.35 | 5.3 | 0.01 | Jan 15, 2021 | An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method | ||
| CVE-2020-26417 | Med | 0.35 | 5.3 | 0.01 | Dec 11, 2020 | Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7. | ||
| CVE-2020-26408 | Med | 0.35 | 5.3 | 0.01 | Dec 11, 2020 | A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile |
- risk 0.35cvss 5.3epss 0.01
A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion.
- risk 0.35cvss 5.3epss 0.01
A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage.
- risk 0.35cvss 6.5epss 0.02
A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users…
- risk 0.35cvss 5.4epss 0.01
Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and…
- risk 0.35cvss 5.3epss 0.01
An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled.…
- risk 0.35cvss 5.4epss 0.01
In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.
- risk 0.35cvss 5.3epss 0.01
A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.
- risk 0.35cvss 5.3epss 0.01
In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.
- risk 0.35cvss 5.4epss 0.01
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
- risk 0.35cvss 5.4epss 0.01
Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status
- risk 0.35cvss 5.4epss 0.01
Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account
- risk 0.35cvss 5.3epss 0.01
Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only
- risk 0.35cvss 5.3epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.
- risk 0.35cvss 5.4epss 0.01
Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted commit to a wiki
- risk 0.35cvss 5.4epss 0.01
A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature.
- risk 0.35cvss 5.3epss 0.01
An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorised user via branch logs.
- risk 0.35cvss 5.3epss 0.02
An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository
- risk 0.35cvss 5.3epss 0.01
An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method
- risk 0.35cvss 5.3epss 0.01
Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.
- risk 0.35cvss 5.3epss 0.01
A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile
Page 38 of 74