VYPR

Vendor CVEs

GitLab Inc.

All CVEs

1,479 total · sorted by risk
  • CVE-2022-2512MedAug 5, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. Membership changes are not reflected in TODO for confidential notes, allowing a…

  • CVE-2022-2498MedAug 5, 2022
    risk 0.42cvss 6.4epss 0.01

    An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.

  • CVE-2022-2326MedAug 5, 2022
    risk 0.42cvss 6.4epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's…

  • CVE-2022-1983MedJul 1, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any location to access Container Registries…

  • CVE-2022-1936MedJun 6, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any…

  • CVE-2022-1935MedJun 6, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any…

  • CVE-2022-1510MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.02

    An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline…

  • CVE-2022-1406MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.01

    Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project

  • CVE-2021-39908MedApr 1, 2022
    risk 0.42cvss 6.5epss 0.01

    In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge…

  • CVE-2022-0549MedMar 28, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under certain conditions, GitLab REST API may allow unprivileged users to add other users to groups…

  • CVE-2022-0152MedJan 18, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the…

  • CVE-2022-0151MedJan 18, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could…

  • CVE-2022-0090MedJan 18, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of…

  • CVE-2021-39939MedDec 13, 2021
    risk 0.42cvss 6.5epss 0.01

    An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted…

  • CVE-2021-39903MedNov 4, 2021
    risk 0.42cvss 6.5epss 0.01

    In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings.

  • CVE-2021-39872MedOct 5, 2021
    risk 0.42cvss 6.5epss 0.01

    In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

  • CVE-2021-39869MedOct 5, 2021
    risk 0.42cvss 6.5epss 0.01

    In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.

  • CVE-2021-39867MedOct 5, 2021
    risk 0.42cvss 6.5epss 0.01

    In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

  • CVE-2021-22252MedAug 23, 2021
    risk 0.42cvss 6.5epss 0.01

    A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to Maintainers

  • CVE-2021-22228MedJul 6, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2. Improper access control allows unauthorised users to access project details using Graphql.

  • CVE-2021-22226MedJul 6, 2021
    risk 0.42cvss 6.5epss 0.01

    Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9

  • CVE-2021-22216MedJun 8, 2021
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

  • CVE-2021-22221MedJun 8, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to…

  • CVE-2021-22217MedJun 8, 2021
    risk 0.42cvss 6.5epss 0.02

    A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request

  • CVE-2020-13351MedNov 17, 2020
    risk 0.42cvss 6.5epss 0.01

    Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.

  • CVE-2020-13346MedOct 7, 2020
    risk 0.42cvss 6.5epss 0.01

    Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

  • CVE-2020-13329MedSep 30, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the blob view feature.

  • CVE-2020-13324MedSep 30, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.

  • CVE-2020-13320MedSep 30, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard.

  • CVE-2020-13296MedSep 30, 2020
    risk 0.42cvss 6.5epss 0.02

    An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens

  • CVE-2020-13310MedSep 14, 2020
    risk 0.42cvss 6.5epss 0.02

    A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the gitlab-runner process crash by sending malformed queries, resulting in a denial of service.

  • CVE-2020-13312MedSep 14, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.

  • CVE-2020-13318MedSep 14, 2020
    risk 0.42cvss 6.4epss 0.01

    A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.

  • CVE-2020-13284MedSep 14, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

  • CVE-2020-13286MedAug 13, 2020
    risk 0.42cvss 6.4epss 0.01

    For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.

  • CVE-2020-13281MedAug 13, 2020
    risk 0.42cvss 6.5epss 0.01

    For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature

  • CVE-2020-13280MedAug 13, 2020
    risk 0.42cvss 6.5epss 0.01

    For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.

  • CVE-2020-11649MedApr 22, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.

  • CVE-2020-10977MedApr 8, 2020
    risk 0.42cvss 5.5epss 0.43

    GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.

  • CVE-2020-10955MedMar 27, 2020
    risk 0.42cvss 6.5epss 0.01

    GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.

  • CVE-2020-10952MedMar 27, 2020
    risk 0.42cvss 6.5epss 0.01

    GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.

  • CVE-2020-10081MedMar 13, 2020
    risk 0.42cvss 6.5epss 0.01

    GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.

  • CVE-2019-13009MedMar 10, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It has Incorrect Access Control.

  • CVE-2019-12429MedMar 10, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.

  • CVE-2013-4582MedJan 28, 2020
    risk 0.42cvss 6.5epss 0.02

    The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to…

  • CVE-2019-5474MedJan 28, 2020
    risk 0.42cvss 6.5epss 0.01

    An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.

  • CVE-2019-19314HigJan 5, 2020
    risk 0.42cvss 7.5epss 0.01

    GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.

  • CVE-2019-19313HigJan 5, 2020
    risk 0.42cvss 7.5epss 0.01

    GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.

  • CVE-2019-15584MedDec 20, 2019
    risk 0.42cvss 6.5epss 0.01

    A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.

  • CVE-2019-5469MedDec 18, 2019
    risk 0.42cvss 6.5epss 0.01

    An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.

Page 11 of 30