VYPR

GitLab

by GitLab Inc.

Source repositories

CVEs (1,462)

  • CVE-2024-12619MedMar 28, 2025
    risk 0.34cvss 5.2epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allowing internal users to gain unauthorized access to internal projects.

  • CVE-2024-10925MedMar 3, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to read Security policy YAML

  • CVE-2024-8650MedDec 16, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

  • CVE-2024-8116MedDec 16, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.

  • CVE-2024-10240MedNov 26, 2024
    risk 0.34cvss 5.3epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a…

  • CVE-2024-8177MedNov 26, 2024
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry.

  • CVE-2024-2191MedJun 27, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

  • CVE-2024-1816MedJun 27, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file.

  • CVE-2024-1525MedFeb 22, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password…

  • CVE-2023-3949MedDec 1, 2023
    risk 0.34cvss 5.3epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects' release descriptions…

  • CVE-2023-3102MedJul 21, 2023
    risk 0.34cvss 5.3epss 0.01

    A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR.

  • CVE-2023-3362MedJul 13, 2023
    risk 0.34cvss 5.3epss 0.01

    An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.

  • CVE-2018-17453MedApr 15, 2023
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.

  • CVE-2023-1167MedApr 5, 2023
    risk 0.34cvss 5.3epss 0.01

    Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.

  • CVE-2022-4167MedJan 12, 2023
    risk 0.34cvss 5.3epss 0.01

    Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.

  • CVE-2022-3286MedOct 17, 2022
    risk 0.34cvss 5.3epss 0.00

    Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

  • CVE-2022-2539MedAug 5, 2022
    risk 0.34cvss 5.3epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.6 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1, allowed a project member to filter issues by contact and organization.

  • CVE-2021-39909MedNov 5, 2021
    risk 0.34cvss 5.3epss 0.01

    Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge…

  • CVE-2021-39882MedOct 5, 2021
    risk 0.34cvss 5.3epss 0.01

    In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

  • CVE-2021-22196MedApr 2, 2021
    risk 0.34cvss 6.3epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in merge request via a specifically crafted branch name.

Page 44 of 74