Vendor CVEs
GitLab Inc.
All CVEs
1,479 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1148 | Med | 0.28 | 5.3 | 0.01 | Apr 4, 2022 | Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse… | ||
| CVE-2022-1105 | Med | 0.28 | 4.3 | 0.01 | Apr 4, 2022 | An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled | ||
| CVE-2022-1100 | Med | 0.28 | 4.3 | 0.01 | Apr 4, 2022 | A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks… | ||
| CVE-2022-1099 | Med | 0.28 | 4.3 | 0.01 | Apr 4, 2022 | Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab | ||
| CVE-2022-0390 | Med | 0.28 | 4.3 | 0.01 | Apr 1, 2022 | Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard. | ||
| CVE-2022-0373 | Med | 0.28 | 4.3 | 0.01 | Apr 1, 2022 | Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address | ||
| CVE-2022-0371 | Med | 0.28 | 4.3 | 0.01 | Mar 28, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their… | ||
| CVE-2021-39876 | Med | 0.28 | 4.3 | 0.01 | Mar 28, 2022 | In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups. | ||
| CVE-2021-39943 | Med | 0.28 | 4.3 | 0.01 | Feb 9, 2022 | An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via… | ||
| CVE-2021-39942 | Med | 0.28 | 4.3 | 0.01 | Jan 18, 2022 | A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package… | ||
| CVE-2021-39892 | Med | 0.28 | 4.3 | 0.01 | Jan 18, 2022 | In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a maintainer role on and disclose email addresses of those users. | ||
| CVE-2021-39940 | Med | 0.28 | 4.3 | 0.01 | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of… | ||
| CVE-2021-39934 | Med | 0.28 | 4.3 | 0.01 | Dec 13, 2021 | Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. | ||
| CVE-2021-39933 | Med | 0.28 | 4.3 | 0.01 | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was… | ||
| CVE-2021-39932 | Med | 0.28 | 4.3 | 0.01 | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for… | ||
| CVE-2021-39930 | Med | 0.28 | 4.3 | 0.01 | Dec 13, 2021 | Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an attacker to access a user's custom project and group templates | ||
| CVE-2021-39917 | Med | 0.28 | 4.3 | 0.01 | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression related to quick actions features was susceptible to… | ||
| CVE-2021-39916 | Med | 0.28 | 4.3 | 0.01 | Dec 13, 2021 | Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from… | ||
| CVE-2021-39905 | Med | 0.28 | 4.3 | 0.01 | Nov 5, 2021 | An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with | ||
| CVE-2021-39904 | Med | 0.28 | 4.3 | 0.01 | Nov 5, 2021 | An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions… | ||
| CVE-2021-39902 | Med | 0.28 | 4.3 | 0.01 | Nov 4, 2021 | Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident. | ||
| CVE-2021-39889 | Med | 0.28 | 4.3 | 0.01 | Oct 5, 2021 | In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch. | ||
| CVE-2021-39870 | Med | 0.28 | 4.3 | 0.01 | Oct 5, 2021 | In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call. | ||
| CVE-2021-22258 | Med | 0.28 | 4.3 | 0.01 | Oct 5, 2021 | The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses | ||
| CVE-2021-39888 | Med | 0.28 | 4.3 | 0.01 | Oct 5, 2021 | In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge… | ||
| CVE-2021-39884 | Med | 0.28 | 4.3 | 0.01 | Oct 5, 2021 | In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project. | ||
| CVE-2021-39883 | Med | 0.28 | 4.3 | 0.01 | Oct 4, 2021 | Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups. | ||
| CVE-2021-39874 | Med | 0.28 | 4.3 | 0.01 | Oct 4, 2021 | In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands. | ||
| CVE-2021-39873 | Med | 0.28 | 4.3 | 0.01 | Oct 4, 2021 | In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to trick users into visiting a malicious website by spoofing the content in an error response. | ||
| CVE-2021-39871 | Med | 0.28 | 4.3 | 0.01 | Oct 4, 2021 | In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call. | ||
| CVE-2021-39868 | Med | 0.28 | 4.3 | 0.01 | Oct 4, 2021 | In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export. | ||
| CVE-2021-22259 | Med | 0.28 | 4.3 | 0.01 | Oct 4, 2021 | A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API. | ||
| CVE-2021-22247 | Med | 0.28 | 4.3 | 0.01 | Aug 25, 2021 | Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics | ||
| CVE-2021-22251 | Med | 0.28 | 4.3 | 0.01 | Aug 23, 2021 | Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings | ||
| CVE-2021-22249 | Med | 0.28 | 4.3 | 0.01 | Aug 23, 2021 | A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group | ||
| CVE-2021-22233 | Med | 0.28 | 4.3 | 0.01 | Jul 7, 2021 | An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details | ||
| CVE-2021-22208 | Med | 0.28 | 4.3 | 0.01 | May 6, 2021 | An issue has been discovered in GitLab affecting versions starting with 13.5 up to 13.9.7. Improper permission check could allow the change of timestamp for issue creation or update. | ||
| CVE-2021-22198 | Med | 0.28 | 4.3 | 0.01 | Apr 2, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects. | ||
| CVE-2021-22177 | Med | 0.28 | 4.3 | 0.01 | Apr 1, 2021 | Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command. | ||
| CVE-2021-22180 | Med | 0.28 | 4.3 | 0.01 | Mar 26, 2021 | An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages. | ||
| CVE-2021-22172 | Med | 0.28 | 4.3 | 0.01 | Mar 26, 2021 | Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page | ||
| CVE-2021-22169 | Med | 0.28 | 4.3 | 0.01 | Mar 24, 2021 | An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages. | ||
| CVE-2021-22176 | Med | 0.28 | 4.3 | 0.01 | Mar 24, 2021 | An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests | ||
| CVE-2021-22187 | Med | 0.28 | 4.3 | 0.01 | Mar 2, 2021 | An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted. | ||
| CVE-2021-22168 | Med | 0.28 | 4.3 | 0.01 | Jan 15, 2021 | A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8. | ||
| CVE-2020-26414 | Med | 0.28 | 4.3 | 0.02 | Jan 15, 2021 | An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string. | ||
| CVE-2020-26411 | Med | 0.28 | 4.3 | 0.01 | Dec 11, 2020 | A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused. | ||
| CVE-2020-26415 | Med | 0.28 | 4.3 | 0.01 | Dec 11, 2020 | Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2. | ||
| CVE-2020-13357 | Med | 0.28 | 4.3 | 0.01 | Dec 11, 2020 | An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project. | ||
| CVE-2020-26409 | Med | 0.28 | 4.3 | 0.01 | Dec 11, 2020 | A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields. |
- risk 0.28cvss 5.3epss 0.01
Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse…
- risk 0.28cvss 4.3epss 0.01
An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled
- risk 0.28cvss 4.3epss 0.01
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks…
- risk 0.28cvss 4.3epss 0.01
Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab
- risk 0.28cvss 4.3epss 0.01
Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.
- risk 0.28cvss 4.3epss 0.01
Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address
- risk 0.28cvss 4.3epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their…
- risk 0.28cvss 4.3epss 0.01
In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.
- risk 0.28cvss 4.3epss 0.01
An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via…
- risk 0.28cvss 4.3epss 0.01
A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package…
- risk 0.28cvss 4.3epss 0.01
In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a maintainer role on and disclose email addresses of those users.
- risk 0.28cvss 4.3epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of…
- risk 0.28cvss 4.3epss 0.01
Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
- risk 0.28cvss 4.3epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was…
- risk 0.28cvss 4.3epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for…
- risk 0.28cvss 4.3epss 0.01
Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an attacker to access a user's custom project and group templates
- risk 0.28cvss 4.3epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression related to quick actions features was susceptible to…
- risk 0.28cvss 4.3epss 0.01
Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from…
- risk 0.28cvss 4.3epss 0.01
An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with
- risk 0.28cvss 4.3epss 0.01
An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions…
- risk 0.28cvss 4.3epss 0.01
Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident.
- risk 0.28cvss 4.3epss 0.01
In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.
- risk 0.28cvss 4.3epss 0.01
In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.
- risk 0.28cvss 4.3epss 0.01
The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses
- risk 0.28cvss 4.3epss 0.01
In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge…
- risk 0.28cvss 4.3epss 0.01
In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.
- risk 0.28cvss 4.3epss 0.01
Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.
- risk 0.28cvss 4.3epss 0.01
In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands.
- risk 0.28cvss 4.3epss 0.01
In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to trick users into visiting a malicious website by spoofing the content in an error response.
- risk 0.28cvss 4.3epss 0.01
In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call.
- risk 0.28cvss 4.3epss 0.01
In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.
- risk 0.28cvss 4.3epss 0.01
A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.
- risk 0.28cvss 4.3epss 0.01
Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics
- risk 0.28cvss 4.3epss 0.01
Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings
- risk 0.28cvss 4.3epss 0.01
A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group
- risk 0.28cvss 4.3epss 0.01
An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details
- risk 0.28cvss 4.3epss 0.01
An issue has been discovered in GitLab affecting versions starting with 13.5 up to 13.9.7. Improper permission check could allow the change of timestamp for issue creation or update.
- risk 0.28cvss 4.3epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects.
- risk 0.28cvss 4.3epss 0.01
Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.
- risk 0.28cvss 4.3epss 0.01
An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.
- risk 0.28cvss 4.3epss 0.01
Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page
- risk 0.28cvss 4.3epss 0.01
An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.
- risk 0.28cvss 4.3epss 0.01
An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests
- risk 0.28cvss 4.3epss 0.01
An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted.
- risk 0.28cvss 4.3epss 0.01
A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.
- risk 0.28cvss 4.3epss 0.02
An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.
- risk 0.28cvss 4.3epss 0.01
A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.
- risk 0.28cvss 4.3epss 0.01
Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.
- risk 0.28cvss 4.3epss 0.01
A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.
Page 23 of 30