VYPR

Vendor CVEs

GitLab Inc.

All CVEs

1,479 total · sorted by risk
  • CVE-2021-39915MedDec 13, 2021
    risk 0.35cvss 5.3epss 0.01

    Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on…

  • CVE-2021-39912MedNov 5, 2021
    risk 0.35cvss 5.3epss 0.01

    A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion.

  • CVE-2021-39907MedNov 5, 2021
    risk 0.35cvss 5.3epss 0.01

    A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage.

  • CVE-2021-39880MedOct 5, 2021
    risk 0.35cvss 6.5epss 0.02

    A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users…

  • CVE-2021-22262MedOct 5, 2021
    risk 0.35cvss 5.4epss 0.01

    Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and…

  • CVE-2021-22257MedOct 5, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled.…

  • CVE-2021-39894MedOct 5, 2021
    risk 0.35cvss 5.4epss 0.01

    In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

  • CVE-2021-39893MedOct 5, 2021
    risk 0.35cvss 5.3epss 0.01

    A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

  • CVE-2021-39875MedOct 5, 2021
    risk 0.35cvss 5.3epss 0.01

    In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.

  • CVE-2021-39866MedOct 5, 2021
    risk 0.35cvss 5.4epss 0.01

    A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

  • CVE-2021-22256MedAug 25, 2021
    risk 0.35cvss 5.4epss 0.01

    Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

  • CVE-2021-22250MedAug 25, 2021
    risk 0.35cvss 5.4epss 0.01

    Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account

  • CVE-2021-22248MedAug 23, 2021
    risk 0.35cvss 5.3epss 0.01

    Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only

  • CVE-2021-22210MedMay 6, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.

  • CVE-2021-22185MedMar 24, 2021
    risk 0.35cvss 5.4epss 0.01

    Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted commit to a wiki

  • CVE-2021-22179MedMar 24, 2021
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature.

  • CVE-2021-22188MedMar 3, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorised user via branch logs.

  • CVE-2021-22167MedJan 15, 2021
    risk 0.35cvss 5.3epss 0.02

    An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository

  • CVE-2021-22166MedJan 15, 2021
    risk 0.35cvss 5.3epss 0.01

    An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method

  • CVE-2020-26417MedDec 11, 2020
    risk 0.35cvss 5.3epss 0.01

    Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.

  • CVE-2020-26408MedDec 11, 2020
    risk 0.35cvss 5.3epss 0.01

    A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile

  • CVE-2020-26406MedNov 17, 2020
    risk 0.35cvss 5.3epss 0.01

    Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects.…

  • CVE-2020-13338MedOct 2, 2020
    risk 0.35cvss 5.4epss 0.01

    An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references.

  • CVE-2020-13331MedSep 30, 2020
    risk 0.35cvss 5.4epss 0.01

    An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges.

  • CVE-2020-13309MedSep 14, 2020
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature.

  • CVE-2020-13317MedSep 14, 2020
    risk 0.35cvss 6.5epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the GraphQL api allowed a maintainer to delete a repository.

  • CVE-2020-13316MedSep 14, 2020
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.

  • CVE-2020-13289MedSep 14, 2020
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.

  • CVE-2020-13295MedAug 10, 2020
    risk 0.35cvss 5.4epss 0.01

    For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.

  • CVE-2020-15525MedJul 7, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.

  • CVE-2020-13264MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token

  • CVE-2020-13261MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code

  • CVE-2020-14155MedJun 15, 2020
    risk 0.35cvss 5.3epss 0.04

    libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

  • CVE-2020-13268MedJun 10, 2020
    risk 0.35cvss 5.3epss 0.01

    A specially crafted request could be used to confirm the existence of files hosted on object storage services, without disclosing their contents. This vulnerability affects GitLab CE/EE 12.10 and later through 13.0.1

  • CVE-2020-12448MedMay 7, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.

  • CVE-2020-12277MedApr 29, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.

  • CVE-2020-12275MedApr 29, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snippet through the API.

  • CVE-2020-10978MedApr 8, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.

  • CVE-2020-10090MedMar 13, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.

  • CVE-2020-10086MedMar 13, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.

  • CVE-2020-10085MedMar 13, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.

  • CVE-2020-10084MedMar 13, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace

  • CVE-2020-10082MedMar 13, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab 12.2 through 12.8.1 allows Denial of Service. A denial of service vulnerability impacting the designs for public issues was discovered.

  • CVE-2020-10080MedMar 13, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.

  • CVE-2020-10079MedMar 13, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.

  • CVE-2020-10535MedMar 12, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.

  • CVE-2019-13004MedMar 10, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2).

  • CVE-2019-12445MedMar 10, 2020
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.

  • CVE-2019-12433MedMar 10, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settings allow creating internal projects in private groups, leading to multiple permission issues.

  • CVE-2020-7977MedFeb 5, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.

Page 16 of 30