VYPR

Vendor CVEs

GitLab Inc.

All CVEs

1,479 total · sorted by risk
  • CVE-2022-1148MedApr 4, 2022
    risk 0.28cvss 5.3epss 0.01

    Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse…

  • CVE-2022-1105MedApr 4, 2022
    risk 0.28cvss 4.3epss 0.01

    An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled

  • CVE-2022-1100MedApr 4, 2022
    risk 0.28cvss 4.3epss 0.01

    A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks…

  • CVE-2022-1099MedApr 4, 2022
    risk 0.28cvss 4.3epss 0.01

    Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab

  • CVE-2022-0390MedApr 1, 2022
    risk 0.28cvss 4.3epss 0.01

    Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

  • CVE-2022-0373MedApr 1, 2022
    risk 0.28cvss 4.3epss 0.01

    Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address

  • CVE-2022-0371MedMar 28, 2022
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their…

  • CVE-2021-39876MedMar 28, 2022
    risk 0.28cvss 4.3epss 0.01

    In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.

  • CVE-2021-39943MedFeb 9, 2022
    risk 0.28cvss 4.3epss 0.01

    An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via…

  • CVE-2021-39942MedJan 18, 2022
    risk 0.28cvss 4.3epss 0.01

    A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package…

  • CVE-2021-39892MedJan 18, 2022
    risk 0.28cvss 4.3epss 0.01

    In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a maintainer role on and disclose email addresses of those users.

  • CVE-2021-39940MedDec 13, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of…

  • CVE-2021-39934MedDec 13, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

  • CVE-2021-39933MedDec 13, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was…

  • CVE-2021-39932MedDec 13, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for…

  • CVE-2021-39930MedDec 13, 2021
    risk 0.28cvss 4.3epss 0.01

    Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an attacker to access a user's custom project and group templates

  • CVE-2021-39917MedDec 13, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression related to quick actions features was susceptible to…

  • CVE-2021-39916MedDec 13, 2021
    risk 0.28cvss 4.3epss 0.01

    Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from…

  • CVE-2021-39905MedNov 5, 2021
    risk 0.28cvss 4.3epss 0.01

    An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with

  • CVE-2021-39904MedNov 5, 2021
    risk 0.28cvss 4.3epss 0.01

    An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions…

  • CVE-2021-39902MedNov 4, 2021
    risk 0.28cvss 4.3epss 0.01

    Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident.

  • CVE-2021-39889MedOct 5, 2021
    risk 0.28cvss 4.3epss 0.01

    In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

  • CVE-2021-39870MedOct 5, 2021
    risk 0.28cvss 4.3epss 0.01

    In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.

  • CVE-2021-22258MedOct 5, 2021
    risk 0.28cvss 4.3epss 0.01

    The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

  • CVE-2021-39888MedOct 5, 2021
    risk 0.28cvss 4.3epss 0.01

    In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge…

  • CVE-2021-39884MedOct 5, 2021
    risk 0.28cvss 4.3epss 0.01

    In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

  • CVE-2021-39883MedOct 4, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.

  • CVE-2021-39874MedOct 4, 2021
    risk 0.28cvss 4.3epss 0.01

    In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands.

  • CVE-2021-39873MedOct 4, 2021
    risk 0.28cvss 4.3epss 0.01

    In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to trick users into visiting a malicious website by spoofing the content in an error response.

  • CVE-2021-39871MedOct 4, 2021
    risk 0.28cvss 4.3epss 0.01

    In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call.

  • CVE-2021-39868MedOct 4, 2021
    risk 0.28cvss 4.3epss 0.01

    In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.

  • CVE-2021-22259MedOct 4, 2021
    risk 0.28cvss 4.3epss 0.01

    A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

  • CVE-2021-22247MedAug 25, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics

  • CVE-2021-22251MedAug 23, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings

  • CVE-2021-22249MedAug 23, 2021
    risk 0.28cvss 4.3epss 0.01

    A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group

  • CVE-2021-22233MedJul 7, 2021
    risk 0.28cvss 4.3epss 0.01

    An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details

  • CVE-2021-22208MedMay 6, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab affecting versions starting with 13.5 up to 13.9.7. Improper permission check could allow the change of timestamp for issue creation or update.

  • CVE-2021-22198MedApr 2, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects.

  • CVE-2021-22177MedApr 1, 2021
    risk 0.28cvss 4.3epss 0.01

    Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.

  • CVE-2021-22180MedMar 26, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.

  • CVE-2021-22172MedMar 26, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page

  • CVE-2021-22169MedMar 24, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.

  • CVE-2021-22176MedMar 24, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests

  • CVE-2021-22187MedMar 2, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted.

  • CVE-2021-22168MedJan 15, 2021
    risk 0.28cvss 4.3epss 0.01

    A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.

  • CVE-2020-26414MedJan 15, 2021
    risk 0.28cvss 4.3epss 0.02

    An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

  • CVE-2020-26411MedDec 11, 2020
    risk 0.28cvss 4.3epss 0.01

    A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.

  • CVE-2020-26415MedDec 11, 2020
    risk 0.28cvss 4.3epss 0.01

    Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

  • CVE-2020-13357MedDec 11, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

  • CVE-2020-26409MedDec 11, 2020
    risk 0.28cvss 4.3epss 0.01

    A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

Page 23 of 30