VYPR

GitLab

by GitLab Inc.

Source repositories

CVEs (1,433)

  • CVE-2021-22169MedMar 24, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.

  • CVE-2021-22176MedMar 24, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests

  • CVE-2021-22187MedMar 2, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted.

  • CVE-2021-22168MedJan 15, 2021
    risk 0.28cvss 4.3epss 0.01

    A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.

  • CVE-2020-26414MedJan 15, 2021
    risk 0.28cvss 4.3epss 0.02

    An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

  • CVE-2020-26411MedDec 11, 2020
    risk 0.28cvss 4.3epss 0.01

    A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.

  • CVE-2020-26415MedDec 11, 2020
    risk 0.28cvss 4.3epss 0.01

    Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

  • CVE-2020-13357MedDec 11, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

  • CVE-2020-26409MedDec 11, 2020
    risk 0.28cvss 4.3epss 0.01

    A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

  • CVE-2020-13349MedNov 17, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted in the Advanced Search feature susceptible to catastrophic backtracking. Affected versions are >=8.12, <13.3.9,>=13.4, <13.4.5,>=13.5,…

  • CVE-2020-13354MedNov 17, 2020
    risk 0.28cvss 4.3epss 0.01

    A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9.

  • CVE-2020-13335MedOct 7, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.

  • CVE-2020-13333MedOct 6, 2020
    risk 0.28cvss 4.3epss 0.02

    A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.

  • CVE-2020-13326MedSep 30, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the restriction for Github project import could be bypassed.

  • CVE-2020-13319MedSep 30, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue.

  • CVE-2020-13313MedSep 14, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control.

  • CVE-2020-13311MedSep 14, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface.

  • CVE-2020-13287MedSep 14, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues

  • CVE-2020-13265MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

  • CVE-2020-13266MedJun 9, 2020
    risk 0.28cvss 4.3epss 0.01

    Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions

Page 56 of 72