VYPR

GitLab

by GitLab Inc.

Source repositories

CVEs (1,433)

  • CVE-2023-0756MedMay 3, 2023
    risk 0.31cvss 4.8epss 0.01

    An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories…

  • CVE-2022-3726MedNov 10, 2022
    risk 0.31cvss 4.8epss 0.01

    Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's…

  • CVE-2022-3486MedNov 9, 2022
    risk 0.31cvss 4.7epss 0.01

    An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.

  • CVE-2022-2250MedJul 1, 2022
    risk 0.31cvss 4.7epss 0.02

    An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.

  • CVE-2022-1120MedApr 4, 2022
    risk 0.31cvss 4.8epss 0.01

    Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

  • CVE-2022-0741MedApr 1, 2022
    risk 0.31cvss 5.8epss 0.01

    Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables via specially crafted email addresses.

  • CVE-2022-0283MedMar 28, 2022
    risk 0.31cvss 4.7epss 0.01

    An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.

  • CVE-2021-22225MedJul 7, 2021
    risk 0.31cvss 4.7epss 0.01

    Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

  • CVE-2020-13358MedNov 17, 2020
    risk 0.31cvss 4.7epss 0.00

    A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

  • CVE-2020-13328MedSep 30, 2020
    risk 0.31cvss 4.8epss 0.01

    An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. GitLab was vulnerable to a stored XSS by using the PyPi files API.

  • CVE-2020-12276MedApr 29, 2020
    risk 0.31cvss 4.8epss 0.01

    GitLab 9.5.9 through 12.9 is vulnerable to stored XSS in an admin notification feature.

  • CVE-2019-19312MedJan 5, 2020
    risk 0.31cvss 5.8epss 0.01

    GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

  • CVE-2026-1094MedFeb 11, 2026
    risk 0.30cvss 4.6epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an authenticated developer to hide specially crafted file changes from the WebUI.

  • CVE-2025-0605MedMay 22, 2025
    risk 0.30cvss 4.6epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

  • CVE-2023-6051MedDec 15, 2023
    risk 0.30cvss 5.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific…

  • CVE-2025-2867MedMar 27, 2025
    risk 0.29cvss 4.4epss 0.00

    An issue has been discovered in the GitLab Duo with Amazon Q affecting all versions from 17.8 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A specifically crafted issue could manipulate AI-assisted development features to potentially expose sensitive project data…

  • CVE-2024-12380MedMar 13, 2025
    risk 0.29cvss 4.4epss 0.01

    An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive…

  • CVE-2024-8266MedFeb 13, 2025
    risk 0.29cvss 4.4epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.

  • CVE-2024-6356MedFeb 5, 2025
    risk 0.29cvss 4.4epss 0.00

    An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project access for Security policy bot.

  • CVE-2024-8631MedSep 12, 2024
    risk 0.29cvss 5.5epss 0.01

    A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include…

Page 46 of 72