VYPR

GitLab

by GitLab Inc.

Source repositories

CVEs (1,462)

  • CVE-2024-7060LowJul 24, 2024
    risk 0.17cvss 2.6epss 0.00

    An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.

  • CVE-2023-4912LowDec 1, 2023
    risk 0.17cvss 2.6epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using…

  • CVE-2023-1279LowSep 1, 2023
    risk 0.17cvss 2.6epss 0.00

    An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 where it was possible to create a URL that would redirect to a different project.

  • CVE-2023-2013LowJun 7, 2023
    risk 0.17cvss 2.6epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An issue was found that allows someone to abuse a discrepancy between the Web…

  • CVE-2022-2281LowJul 1, 2022
    risk 0.17cvss 2.6epss 0.01

    An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.

  • CVE-2022-1433LowMay 11, 2022
    risk 0.17cvss 2.6epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously…

  • CVE-2022-1157LowApr 11, 2022
    risk 0.17cvss 2.6epss 0.01

    Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

  • CVE-2022-1188LowApr 4, 2022
    risk 0.17cvss 3.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.

  • CVE-2021-39910LowDec 13, 2021
    risk 0.17cvss 2.6epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.

  • CVE-2021-39897LowNov 5, 2021
    risk 0.17cvss 2.6epss 0.01

    Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the subgroup is transferred

  • CVE-2021-39886LowOct 5, 2021
    risk 0.17cvss 2.6epss 0.01

    Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

  • CVE-2021-32823LowJun 24, 2021
    risk 0.17cvss 3.7epss 0.02

    In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit. In…

  • CVE-2021-22218LowJun 8, 2021
    risk 0.17cvss 2.6epss 0.00

    All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed…

  • CVE-2019-7176LowSep 9, 2019
    risk 0.17cvss 3.7epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they…

  • CVE-2024-5528LowFeb 5, 2025
    risk 0.16cvss 3.5epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.

  • CVE-2024-6446LowSep 12, 2024
    risk 0.16cvss 3.5epss 0.00

    An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.3 prior to 17.3.2. A crafted URL could be used to trick a victim to trust an attacker controlled application.

  • CVE-2022-1111LowApr 4, 2022
    risk 0.16cvss 2.4epss 0.01

    A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

  • CVE-2022-0093LowJan 18, 2022
    risk 0.16cvss 3.5epss 0.01

    An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

  • CVE-2021-22202LowApr 2, 2021
    risk 0.16cvss 2.4epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all previous versions. If the victim is an admin, it was possible to issue a CSRF in System hooks through the API.

  • CVE-2025-12697LowMar 11, 2026
    risk 0.14cvss 2.2epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API credentials under certain conditions.

Page 71 of 74