Vendor CVEs
GitLab Inc.
All CVEs
1,479 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-2512 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. Membership changes are not reflected in TODO for confidential notes, allowing a… | ||
| CVE-2022-2498 | Med | 0.42 | 6.4 | 0.01 | Aug 5, 2022 | An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author. | ||
| CVE-2022-2326 | Med | 0.42 | 6.4 | 0.01 | Aug 5, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's… | ||
| CVE-2022-1983 | Med | 0.42 | 6.5 | 0.01 | Jul 1, 2022 | Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any location to access Container Registries… | ||
| CVE-2022-1936 | Med | 0.42 | 6.5 | 0.01 | Jun 6, 2022 | Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any… | ||
| CVE-2022-1935 | Med | 0.42 | 6.5 | 0.01 | Jun 6, 2022 | Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any… | ||
| CVE-2022-1510 | Med | 0.42 | 6.5 | 0.02 | May 11, 2022 | An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline… | ||
| CVE-2022-1406 | Med | 0.42 | 6.5 | 0.01 | May 11, 2022 | Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project | ||
| CVE-2021-39908 | Med | 0.42 | 6.5 | 0.01 | Apr 1, 2022 | In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge… | ||
| CVE-2022-0549 | Med | 0.42 | 6.5 | 0.01 | Mar 28, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under certain conditions, GitLab REST API may allow unprivileged users to add other users to groups… | ||
| CVE-2022-0152 | Med | 0.42 | 6.5 | 0.01 | Jan 18, 2022 | An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the… | ||
| CVE-2022-0151 | Med | 0.42 | 6.5 | 0.01 | Jan 18, 2022 | An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could… | ||
| CVE-2022-0090 | Med | 0.42 | 6.5 | 0.01 | Jan 18, 2022 | An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of… | ||
| CVE-2021-39939 | Med | 0.42 | 6.5 | 0.01 | Dec 13, 2021 | An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted… | ||
| CVE-2021-39903 | Med | 0.42 | 6.5 | 0.01 | Nov 4, 2021 | In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings. | ||
| CVE-2021-39872 | Med | 0.42 | 6.5 | 0.01 | Oct 5, 2021 | In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration. | ||
| CVE-2021-39869 | Med | 0.42 | 6.5 | 0.01 | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project. | ||
| CVE-2021-39867 | Med | 0.42 | 6.5 | 0.01 | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks. | ||
| CVE-2021-22252 | Med | 0.42 | 6.5 | 0.01 | Aug 23, 2021 | A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to Maintainers | ||
| CVE-2021-22228 | Med | 0.42 | 6.5 | 0.01 | Jul 6, 2021 | An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2. Improper access control allows unauthorised users to access project details using Graphql. | ||
| CVE-2021-22226 | Med | 0.42 | 6.5 | 0.01 | Jul 6, 2021 | Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9 | ||
| CVE-2021-22216 | Med | 0.42 | 6.5 | 0.01 | Jun 8, 2021 | A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description | ||
| CVE-2021-22221 | Med | 0.42 | 6.5 | 0.01 | Jun 8, 2021 | An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to… | ||
| CVE-2021-22217 | Med | 0.42 | 6.5 | 0.02 | Jun 8, 2021 | A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request | ||
| CVE-2020-13351 | Med | 0.42 | 6.5 | 0.01 | Nov 17, 2020 | Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2. | ||
| CVE-2020-13346 | Med | 0.42 | 6.5 | 0.01 | Oct 7, 2020 | Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API. | ||
| CVE-2020-13329 | Med | 0.42 | 6.5 | 0.01 | Sep 30, 2020 | An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the blob view feature. | ||
| CVE-2020-13324 | Med | 0.42 | 6.5 | 0.01 | Sep 30, 2020 | A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API. | ||
| CVE-2020-13320 | Med | 0.42 | 6.5 | 0.01 | Sep 30, 2020 | An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard. | ||
| CVE-2020-13296 | Med | 0.42 | 6.5 | 0.02 | Sep 30, 2020 | An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens | ||
| CVE-2020-13310 | Med | 0.42 | 6.5 | 0.02 | Sep 14, 2020 | A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the gitlab-runner process crash by sending malformed queries, resulting in a denial of service. | ||
| CVE-2020-13312 | Med | 0.42 | 6.5 | 0.01 | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter. | ||
| CVE-2020-13318 | Med | 0.42 | 6.4 | 0.01 | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack. | ||
| CVE-2020-13284 | Med | 0.42 | 6.5 | 0.01 | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token | ||
| CVE-2020-13286 | Med | 0.42 | 6.4 | 0.01 | Aug 13, 2020 | For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery. | ||
| CVE-2020-13281 | Med | 0.42 | 6.5 | 0.01 | Aug 13, 2020 | For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature | ||
| CVE-2020-13280 | Med | 0.42 | 6.5 | 0.01 | Aug 13, 2020 | For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message. | ||
| CVE-2020-11649 | Med | 0.42 | 6.5 | 0.01 | Apr 22, 2020 | An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted. | ||
| CVE-2020-10977 | Med | 0.42 | 5.5 | 0.43 | Apr 8, 2020 | GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects. | ||
| CVE-2020-10955 | Med | 0.42 | 6.5 | 0.01 | Mar 27, 2020 | GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders. | ||
| CVE-2020-10952 | Med | 0.42 | 6.5 | 0.01 | Mar 27, 2020 | GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images. | ||
| CVE-2020-10081 | Med | 0.42 | 6.5 | 0.01 | Mar 13, 2020 | GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user. | ||
| CVE-2019-13009 | Med | 0.42 | 6.5 | 0.01 | Mar 10, 2020 | An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It has Incorrect Access Control. | ||
| CVE-2019-12429 | Med | 0.42 | 6.5 | 0.01 | Mar 10, 2020 | An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control. | ||
| CVE-2013-4582 | Med | 0.42 | 6.5 | 0.02 | Jan 28, 2020 | The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to… | ||
| CVE-2019-5474 | Med | 0.42 | 6.5 | 0.01 | Jan 28, 2020 | An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions. | ||
| CVE-2019-19314 | Hig | 0.42 | 7.5 | 0.01 | Jan 5, 2020 | GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext. | ||
| CVE-2019-19313 | Hig | 0.42 | 7.5 | 0.01 | Jan 5, 2020 | GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits. | ||
| CVE-2019-15584 | Med | 0.42 | 6.5 | 0.01 | Dec 20, 2019 | A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page. | ||
| CVE-2019-5469 | Med | 0.42 | 6.5 | 0.01 | Dec 18, 2019 | An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets. |
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. Membership changes are not reflected in TODO for confidential notes, allowing a…
- risk 0.42cvss 6.4epss 0.01
An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.
- risk 0.42cvss 6.4epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's…
- risk 0.42cvss 6.5epss 0.01
Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any location to access Container Registries…
- risk 0.42cvss 6.5epss 0.01
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any…
- risk 0.42cvss 6.5epss 0.01
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any…
- risk 0.42cvss 6.5epss 0.02
An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline…
- risk 0.42cvss 6.5epss 0.01
Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project
- risk 0.42cvss 6.5epss 0.01
In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge…
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under certain conditions, GitLab REST API may allow unprivileged users to add other users to groups…
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the…
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could…
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of…
- risk 0.42cvss 6.5epss 0.01
An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted…
- risk 0.42cvss 6.5epss 0.01
In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings.
- risk 0.42cvss 6.5epss 0.01
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
- risk 0.42cvss 6.5epss 0.01
In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
- risk 0.42cvss 6.5epss 0.01
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
- risk 0.42cvss 6.5epss 0.01
A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to Maintainers
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2. Improper access control allows unauthorised users to access project details using Graphql.
- risk 0.42cvss 6.5epss 0.01
Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9
- risk 0.42cvss 6.5epss 0.01
A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to…
- risk 0.42cvss 6.5epss 0.02
A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request
- risk 0.42cvss 6.5epss 0.01
Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.
- risk 0.42cvss 6.5epss 0.01
Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the blob view feature.
- risk 0.42cvss 6.5epss 0.01
A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard.
- risk 0.42cvss 6.5epss 0.02
An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens
- risk 0.42cvss 6.5epss 0.02
A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the gitlab-runner process crash by sending malformed queries, resulting in a denial of service.
- risk 0.42cvss 6.5epss 0.01
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.
- risk 0.42cvss 6.4epss 0.01
A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.
- risk 0.42cvss 6.5epss 0.01
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token
- risk 0.42cvss 6.4epss 0.01
For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.
- risk 0.42cvss 6.5epss 0.01
For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature
- risk 0.42cvss 6.5epss 0.01
For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.
- risk 0.42cvss 5.5epss 0.43
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
- risk 0.42cvss 6.5epss 0.01
GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.
- risk 0.42cvss 6.5epss 0.01
GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.
- risk 0.42cvss 6.5epss 0.01
GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It has Incorrect Access Control.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.
- risk 0.42cvss 6.5epss 0.02
The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to…
- risk 0.42cvss 6.5epss 0.01
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.
- risk 0.42cvss 7.5epss 0.01
GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.
- risk 0.42cvss 7.5epss 0.01
GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.
- risk 0.42cvss 6.5epss 0.01
A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.
- risk 0.42cvss 6.5epss 0.01
An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.
Page 11 of 30