VYPR

Vendor CVEs

GitLab Inc.

All CVEs

1,479 total · sorted by risk
  • CVE-2021-39891MedOct 5, 2021
    risk 0.38cvss 5.9epss 0.01

    In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

  • CVE-2021-39878MedOct 5, 2021
    risk 0.38cvss 5.8epss 0.01

    A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

  • CVE-2021-22229MedJul 6, 2021
    risk 0.38cvss 5.9epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member.

  • CVE-2021-22200MedApr 2, 2021
    risk 0.38cvss 5.9epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an internal repository through a public project fork as an anonymous user.

  • CVE-2021-22189MedMar 4, 2021
    risk 0.38cvss 5.9epss 0.01

    Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.

  • CVE-2020-13334MedOct 7, 2020
    risk 0.38cvss 5.9epss 0.02

    In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentiality attribute of issue via mutation GraphQL query

  • CVE-2019-13010MedMar 10, 2020
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It allows Uncontrolled Resource Consumption.

  • CVE-2018-19572MedJul 10, 2019
    risk 0.38cvss 5.9epss 0.01

    GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

  • CVE-2019-9172MedApr 17, 2019
    risk 0.38cvss 5.9epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 2 of 5).

  • CVE-2017-17716MedDec 17, 2017
    risk 0.38cvss 5.9epss 0.01

    GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release announcement. This issue occurred because code was not merged. This is related to use of the omniauth-ldap library and the…

  • CVE-2026-1516MedApr 8, 2026
    risk 0.37cvss 5.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of users viewing the report via specially crafted…

  • CVE-2024-8641MedSep 12, 2024
    risk 0.37cvss 6.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLab session token belonging to…

  • CVE-2024-6502MedAug 22, 2024
    risk 0.37cvss 5.7epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prior to 17.2.4, and starting from 17.3 prior to 17.3.1, which allows an attacker to create a branch with the same name as a deleted tag.

  • CVE-2024-3035MedAug 8, 2024
    risk 0.37cvss 6.8epss 0.00

    A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.

  • CVE-2024-6329MedAug 8, 2024
    risk 0.37cvss 5.7epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.

  • CVE-2024-4597MedMay 14, 2024
    risk 0.37cvss 5.7epss 0.00

    An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.

  • CVE-2023-3444MedJul 13, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches.

  • CVE-2023-1178MedMay 3, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled…

  • CVE-2023-1708MedApr 5, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine.

  • CVE-2022-4331MedMar 9, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group,…

  • CVE-2022-4092MedJan 26, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input.

  • CVE-2022-2907MedJan 17, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It was possible to read repository content by an unauthorised user if a project…

  • CVE-2021-22194MedMar 26, 2021
    risk 0.37cvss 5.7epss 0.00

    In all versions of GitLab, marshalled session keys were being stored in Redis.

  • CVE-2020-26413MedDec 11, 2020
    risk 0.37cvss 5.3epss 0.35

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

  • CVE-2020-13348MedNov 17, 2020
    risk 0.37cvss 5.7epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

  • CVE-2020-13344MedOct 8, 2020
    risk 0.37cvss 5.7epss 0.00

    An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are stored in plain-text in Redis which allows attacker with Redis access to authenticate as any user that has a session stored in Redis

  • CVE-2026-3035MedAug 26, 2026
    risk 0.36cvss 5.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with project Maintainer permissions could have accessed the terminal of a protected…

  • CVE-2024-4278MedSep 26, 2024
    risk 0.36cvss 5.5epss 0.00

    An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy…

  • CVE-2023-4378MedSep 1, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A malicious Maintainer can, under specific circumstances, leak the sentry token by…

  • CVE-2023-3950MedSep 1, 2023
    risk 0.36cvss 5.5epss 0.00

    An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the…

  • CVE-2023-2620MedJul 13, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other…

  • CVE-2023-0838MedApr 5, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix…

  • CVE-2023-0483MedMar 9, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by…

  • CVE-2022-4054MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to leak a webhook secret token by changing the…

  • CVE-2022-3902MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to unmask webhook secret tokens by reviewing the…

  • CVE-2022-4365MedJan 12, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by changing the configured URL in…

  • CVE-2022-4342MedJan 12, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of…

  • CVE-2022-3483MedNov 9, 2022
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could exfiltrate a Datadog integration's access token by…

  • CVE-2022-2882MedOct 28, 2022
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by…

  • CVE-2021-22263MedOct 11, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project…

  • CVE-2021-22236MedAug 25, 2021
    risk 0.36cvss 5.5epss 0.01

    Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

  • CVE-2020-26407MedDec 10, 2020
    risk 0.36cvss 5.5epss 0.01

    A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

  • CVE-2020-13339MedOct 8, 2020
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab affecting all versions before 13.2.10, 13.3.7 and 13.4.2: XSS in SVG File Preview. Overall impact is limited due to the current user only being impacted.

  • CVE-2020-13345MedOct 6, 2020
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes

  • CVE-2020-13301MedSep 14, 2020
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standalone vulnerability page.

  • CVE-2020-13288MedAug 12, 2020
    risk 0.36cvss 5.5epss 0.04

    In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page

  • CVE-2019-9221MedMay 29, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 3 of 5).

  • CVE-2026-12910MedSep 15, 2026
    risk 0.35cvss 5.4epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to bypass SAML SSO sign-in restrictions and authenticate without SSO…

  • CVE-2026-6269MedJun 11, 2026
    risk 0.35cvss 5.4epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to modify hidden merge requests…

  • CVE-2026-6335MedMay 14, 2026
    risk 0.35cvss 5.4epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.3 that under certain conditions could have allowed an authenticated user to execute arbitrary code in another user's browser session due to improper sanitization.

Page 14 of 30