GitLab
by GitLab Inc.
Source repositories
CVEs (1,462)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-26406 | Med | 0.35 | 5.3 | 0.01 | Nov 17, 2020 | Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects.… | ||
| CVE-2020-13338 | Med | 0.35 | 5.4 | 0.01 | Oct 2, 2020 | An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references. | ||
| CVE-2020-13331 | Med | 0.35 | 5.4 | 0.01 | Sep 30, 2020 | An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges. | ||
| CVE-2020-13309 | Med | 0.35 | 5.4 | 0.01 | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature. | ||
| CVE-2020-13317 | Med | 0.35 | 6.5 | 0.01 | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the GraphQL api allowed a maintainer to delete a repository. | ||
| CVE-2020-13316 | Med | 0.35 | 5.4 | 0.01 | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line. | ||
| CVE-2020-13289 | Med | 0.35 | 5.4 | 0.01 | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated. | ||
| CVE-2020-15525 | Med | 0.35 | 5.3 | 0.01 | Jul 7, 2020 | GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint. | ||
| CVE-2020-13264 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token | ||
| CVE-2020-13261 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code | ||
| CVE-2020-14155 | Med | 0.35 | 5.3 | 0.04 | Jun 15, 2020 | libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring. | ||
| CVE-2020-13268 | Med | 0.35 | 5.3 | 0.01 | Jun 10, 2020 | A specially crafted request could be used to confirm the existence of files hosted on object storage services, without disclosing their contents. This vulnerability affects GitLab CE/EE 12.10 and later through 13.0.1 | ||
| CVE-2020-12448 | Med | 0.35 | 5.3 | 0.01 | May 7, 2020 | GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet. | ||
| CVE-2020-12277 | Med | 0.35 | 5.3 | 0.01 | Apr 29, 2020 | GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated. | ||
| CVE-2020-12275 | Med | 0.35 | 5.3 | 0.01 | Apr 29, 2020 | GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snippet through the API. | ||
| CVE-2020-10978 | Med | 0.35 | 5.3 | 0.01 | Apr 8, 2020 | GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API. | ||
| CVE-2020-10090 | Med | 0.35 | 5.3 | 0.01 | Mar 13, 2020 | GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed. | ||
| CVE-2020-10086 | Med | 0.35 | 5.3 | 0.01 | Mar 13, 2020 | GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read. | ||
| CVE-2020-10085 | Med | 0.35 | 5.3 | 0.01 | Mar 13, 2020 | GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles. | ||
| CVE-2020-10084 | Med | 0.35 | 5.3 | 0.01 | Mar 13, 2020 | GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace |
- risk 0.35cvss 5.3epss 0.01
Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects.…
- risk 0.35cvss 5.4epss 0.01
An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references.
- risk 0.35cvss 5.4epss 0.01
An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges.
- risk 0.35cvss 5.4epss 0.01
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature.
- risk 0.35cvss 6.5epss 0.01
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the GraphQL api allowed a maintainer to delete a repository.
- risk 0.35cvss 5.4epss 0.01
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.
- risk 0.35cvss 5.4epss 0.01
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.
- risk 0.35cvss 5.3epss 0.01
GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.
- risk 0.35cvss 5.3epss 0.01
Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token
- risk 0.35cvss 5.3epss 0.01
Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code
- risk 0.35cvss 5.3epss 0.04
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
- risk 0.35cvss 5.3epss 0.01
A specially crafted request could be used to confirm the existence of files hosted on object storage services, without disclosing their contents. This vulnerability affects GitLab CE/EE 12.10 and later through 13.0.1
- risk 0.35cvss 5.3epss 0.01
GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.
- risk 0.35cvss 5.3epss 0.01
GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.
- risk 0.35cvss 5.3epss 0.01
GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snippet through the API.
- risk 0.35cvss 5.3epss 0.01
GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.
- risk 0.35cvss 5.3epss 0.01
GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.
- risk 0.35cvss 5.3epss 0.01
GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.
- risk 0.35cvss 5.3epss 0.01
GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.
- risk 0.35cvss 5.3epss 0.01
GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace
Page 39 of 74