GitLab
by GitLab Inc.
Source repositories
CVEs (1,433)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-22169 | Med | 0.28 | 4.3 | 0.01 | Mar 24, 2021 | An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages. | ||
| CVE-2021-22176 | Med | 0.28 | 4.3 | 0.01 | Mar 24, 2021 | An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests | ||
| CVE-2021-22187 | Med | 0.28 | 4.3 | 0.01 | Mar 2, 2021 | An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted. | ||
| CVE-2021-22168 | Med | 0.28 | 4.3 | 0.01 | Jan 15, 2021 | A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8. | ||
| CVE-2020-26414 | Med | 0.28 | 4.3 | 0.02 | Jan 15, 2021 | An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string. | ||
| CVE-2020-26411 | Med | 0.28 | 4.3 | 0.01 | Dec 11, 2020 | A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused. | ||
| CVE-2020-26415 | Med | 0.28 | 4.3 | 0.01 | Dec 11, 2020 | Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2. | ||
| CVE-2020-13357 | Med | 0.28 | 4.3 | 0.01 | Dec 11, 2020 | An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project. | ||
| CVE-2020-26409 | Med | 0.28 | 4.3 | 0.01 | Dec 11, 2020 | A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields. | ||
| CVE-2020-13349 | Med | 0.28 | 4.3 | 0.01 | Nov 17, 2020 | An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted in the Advanced Search feature susceptible to catastrophic backtracking. Affected versions are >=8.12, <13.3.9,>=13.4, <13.4.5,>=13.5,… | ||
| CVE-2020-13354 | Med | 0.28 | 4.3 | 0.01 | Nov 17, 2020 | A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9. | ||
| CVE-2020-13335 | Med | 0.28 | 4.3 | 0.01 | Oct 7, 2020 | Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group. | ||
| CVE-2020-13333 | Med | 0.28 | 4.3 | 0.02 | Oct 6, 2020 | A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage. | ||
| CVE-2020-13326 | Med | 0.28 | 4.3 | 0.01 | Sep 30, 2020 | A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the restriction for Github project import could be bypassed. | ||
| CVE-2020-13319 | Med | 0.28 | 4.3 | 0.01 | Sep 30, 2020 | An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue. | ||
| CVE-2020-13313 | Med | 0.28 | 4.3 | 0.01 | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control. | ||
| CVE-2020-13311 | Med | 0.28 | 4.3 | 0.01 | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface. | ||
| CVE-2020-13287 | Med | 0.28 | 4.3 | 0.01 | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues | ||
| CVE-2020-13265 | Med | 0.28 | 4.3 | 0.01 | Jun 19, 2020 | User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification | ||
| CVE-2020-13266 | Med | 0.28 | 4.3 | 0.01 | Jun 9, 2020 | Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions |
- risk 0.28cvss 4.3epss 0.01
An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.
- risk 0.28cvss 4.3epss 0.01
An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests
- risk 0.28cvss 4.3epss 0.01
An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted.
- risk 0.28cvss 4.3epss 0.01
A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.
- risk 0.28cvss 4.3epss 0.02
An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.
- risk 0.28cvss 4.3epss 0.01
A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.
- risk 0.28cvss 4.3epss 0.01
Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.
- risk 0.28cvss 4.3epss 0.01
A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.
- risk 0.28cvss 4.3epss 0.01
An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted in the Advanced Search feature susceptible to catastrophic backtracking. Affected versions are >=8.12, <13.3.9,>=13.4, <13.4.5,>=13.5,…
- risk 0.28cvss 4.3epss 0.01
A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9.
- risk 0.28cvss 4.3epss 0.01
Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.
- risk 0.28cvss 4.3epss 0.02
A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.
- risk 0.28cvss 4.3epss 0.01
A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the restriction for Github project import could be bypassed.
- risk 0.28cvss 4.3epss 0.01
An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue.
- risk 0.28cvss 4.3epss 0.01
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control.
- risk 0.28cvss 4.3epss 0.01
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface.
- risk 0.28cvss 4.3epss 0.01
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues
- risk 0.28cvss 4.3epss 0.01
User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification
- risk 0.28cvss 4.3epss 0.01
Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions
Page 56 of 72