VYPR

GitLab

by GitLab Inc.

Source repositories

CVEs (1,462)

  • CVE-2025-1042MedFeb 12, 2025
    risk 0.32cvss 4.9epss 0.00

    An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way.

  • CVE-2024-9623MedOct 10, 2024
    risk 0.32cvss 4.9epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows deploy keys to push to an archived repository.

  • CVE-2024-7554MedAug 8, 2024
    risk 0.32cvss 4.9epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request…

  • CVE-2024-5257MedJul 11, 2024
    risk 0.32cvss 4.9epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

  • CVE-2023-3993MedAug 2, 2023
    risk 0.32cvss 4.9epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Access tokens may have been logged when a query was made to a specific endpoint.

  • CVE-2023-0805MedMay 3, 2023
    risk 0.32cvss 4.9epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to have access to the public projects of a…

  • CVE-2022-2456MedAug 5, 2022
    risk 0.32cvss 4.9epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for malicious group or project maintainers to change their corresponding group or…

  • CVE-2022-0477MedApr 25, 2022
    risk 0.32cvss 4.9epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the…

  • CVE-2021-22253MedAug 23, 2021
    risk 0.32cvss 4.9epss 0.01

    Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed

  • CVE-2021-22230MedJul 7, 2021
    risk 0.32cvss 4.9epss 0.01

    Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2.

  • CVE-2021-22186MedMar 24, 2021
    risk 0.32cvss 4.9epss 0.01

    An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners

  • CVE-2020-13341MedOct 12, 2020
    risk 0.32cvss 4.9epss 0.01

    An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Insufficient permission check allows attacker with developer role to perform various deletions.

  • CVE-2019-13007MedMar 10, 2020
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 11.11 through 12.0.2. When an admin enabled one of the service templates, it was triggering an action that leads to resource depletion. It allows Uncontrolled Resource Consumption.

  • CVE-2019-19310MedJan 3, 2020
    risk 0.32cvss 4.9epss 0.01

    GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure.

  • CVE-2026-19619MedSep 16, 2026
    risk 0.31cvss 4.7epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in the context of a targeted user's…

  • CVE-2023-5512MedDec 15, 2023
    risk 0.31cvss 4.8epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when specific HTML encoding is used for file names leading…

  • CVE-2023-5226MedDec 1, 2023
    risk 0.31cvss 4.8epss 0.01

    An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted…

  • CVE-2023-3401MedAug 2, 2023
    risk 0.31cvss 4.8epss 0.01

    An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. The main branch of a repository with a specially designed name allows an attacker to create repositories…

  • CVE-2023-3500MedAug 2, 2023
    risk 0.31cvss 4.8epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed…

  • CVE-2023-0756MedMay 3, 2023
    risk 0.31cvss 4.8epss 0.01

    An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories…

Page 46 of 74