VYPR

Vendor CVEs

GitLab Inc.

All CVEs

1,450 total · sorted by risk
  • CVE-2023-7028CriKEVJan 12, 2024
    risk 0.88cvss 10.0epss 0.95

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could…

  • CVE-2021-22205CriKEVApr 23, 2021
    risk 0.87cvss 10.0epss 1.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

  • CVE-2023-2825CriMay 26, 2023
    risk 0.74cvss 10.0epss 0.72

    An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

  • CVE-2022-2992CriOct 17, 2022
    risk 0.74cvss 9.9epss 0.86

    A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

  • CVE-2022-2884CriOct 17, 2022
    risk 0.73cvss 9.9epss 0.76

    A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

  • CVE-2022-2185CriJul 1, 2022
    risk 0.71cvss 9.9epss 0.77

    A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code…

  • CVE-2022-1680CriJun 6, 2022
    risk 0.66cvss 9.9epss 0.15

    An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. When group SAML SSO is configured, the SCIM feature (available…

  • CVE-2022-0735CriMar 28, 2022
    risk 0.66cvss 10.0epss 0.13

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an…

  • CVE-2024-0402CriJan 26, 2024
    risk 0.65cvss 9.9epss 0.04

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

  • CVE-2019-9174CriApr 17, 2019
    risk 0.65cvss 10.0epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.

  • CVE-2018-18843CriDec 4, 2018
    risk 0.65cvss 10.0epss 0.02

    The Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.

  • CVE-2026-1868CriFeb 9, 2026
    risk 0.64cvss 9.9epss 0.01

    GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in which AI Gateway was vulnerable to insecure template expansion of user supplied…

  • CVE-2023-2442HigJun 7, 2023
    risk 0.64cvss 8.7epss 0.96

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary…

  • CVE-2018-17452CriApr 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.

  • CVE-2023-0050HigMar 9, 2023
    risk 0.64cvss 8.7epss 0.92

    An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which…

  • CVE-2020-10980CriApr 8, 2020
    risk 0.64cvss 9.8epss 0.02

    GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.

  • CVE-2020-10956CriMar 27, 2020
    risk 0.64cvss 9.8epss 0.01

    GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.

  • CVE-2020-10077CriMar 13, 2020
    risk 0.64cvss 9.8epss 0.01

    GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk.

  • CVE-2020-10074CriMar 13, 2020
    risk 0.64cvss 9.8epss 0.01

    GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.

  • CVE-2019-12443CriMar 10, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks.

  • CVE-2019-12428CriMar 10, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.

  • CVE-2020-8113CriMar 6, 2020
    risk 0.64cvss 9.8epss 0.01

    GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.

  • CVE-2020-8114CriFeb 5, 2020
    risk 0.64cvss 9.8epss 0.01

    GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

  • CVE-2019-5464CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.03

    A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.

  • CVE-2019-15585CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.02

    Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.

  • CVE-2019-19628CriJan 5, 2020
    risk 0.64cvss 9.8epss 0.04

    In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

  • CVE-2019-19088CriJan 3, 2020
    risk 0.64cvss 9.8epss 0.02

    Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.

  • CVE-2019-15741CriSep 16, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation

  • CVE-2019-14943CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

  • CVE-2019-9732CriMay 29, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control.

  • CVE-2019-9485CriMay 29, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

  • CVE-2019-9218CriMay 29, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 1 of 5).

  • CVE-2019-9756CriApr 17, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control, a different vulnerability than CVE-2019-9732.

  • CVE-2019-9217CriApr 17, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. Its User Interface has a Misrepresentation of Critical Information.

  • CVE-2018-18641CriDec 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Cleartext Storage of Sensitive Information.

  • CVE-2018-18649CriNov 29, 2018
    risk 0.64cvss 9.8epss 0.07

    An issue was discovered in the wiki API in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for remote code execution.

  • CVE-2018-16049CriOct 3, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.

  • CVE-2018-8971CriMar 24, 2018
    risk 0.64cvss 9.8epss 0.01

    The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

  • CVE-2017-0916CriMar 21, 2018
    risk 0.64cvss 9.8epss 0.06

    Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

  • CVE-2017-0915CriMar 21, 2018
    risk 0.64cvss 9.8epss 0.06

    Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

  • CVE-2024-6385CriJul 11, 2024
    risk 0.63cvss 9.6epss 0.06

    An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

  • CVE-2024-5655CriJun 27, 2024
    risk 0.63cvss 9.6epss 0.07

    An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.

  • CVE-2023-2478CriMay 8, 2023
    risk 0.63cvss 9.6epss 0.05

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a…

  • CVE-2021-22201CriApr 2, 2021
    risk 0.63cvss 9.6epss 0.03

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server.

  • CVE-2024-7102CriFeb 13, 2025
    risk 0.62cvss 9.6epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.

  • CVE-2024-9164CriOct 11, 2024
    risk 0.62cvss 9.6epss 0.01

    An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.

  • CVE-2021-22242HigAug 25, 2021
    risk 0.62cvss 8.7epss 0.64

    Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

  • CVE-2021-22234CriAug 5, 2021
    risk 0.62cvss 9.6epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files…

  • CVE-2020-13340HigOct 8, 2020
    risk 0.62cvss 8.7epss 0.69

    An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log

  • CVE-2020-13292CriAug 10, 2020
    risk 0.62cvss 9.6epss 0.01

    In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.

Page 1 of 29