VYPR

Vendor CVEs

GitLab Inc.

All CVEs

1,479 total · sorted by risk
  • CVE-2022-2931HigOct 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high…

  • CVE-2022-2229HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects…

  • CVE-2022-0154HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.00

    An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious…

  • CVE-2021-22215HigJun 8, 2021
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects

  • CVE-2021-22209HigMay 6, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.

  • CVE-2021-22203HigApr 2, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7.9 before 13.8.7, all versions starting from 13.9 before 13.9.5, and all versions starting from 13.10 before 13.10.1. A specially crafted Wiki page allowed attackers to read arbitrary files on…

  • CVE-2020-13359HigNov 19, 2020
    risk 0.49cvss 7.6epss 0.01

    The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4,…

  • CVE-2020-13355HigNov 19, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server. Affected versions are: >=8.14, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

  • CVE-2020-13343HigOct 6, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template

  • CVE-2020-13290HigAug 12, 2020
    risk 0.49cvss 7.5epss 0.01

    In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page

  • CVE-2020-13263HigJun 19, 2020
    risk 0.49cvss 7.5epss 0.01

    An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.

  • CVE-2020-13274HigJun 19, 2020
    risk 0.49cvss 7.5epss 0.01

    A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1

  • CVE-2020-13273HigJun 19, 2020
    risk 0.49cvss 7.5epss 0.01

    A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1

  • CVE-2020-13272HigJun 19, 2020
    risk 0.49cvss 7.5epss 0.01

    OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow

  • CVE-2020-13270HigJun 10, 2020
    risk 0.49cvss 7.5epss 0.01

    Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API

  • CVE-2020-11506HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via request smuggling.

  • CVE-2020-11505HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead to NuGet package and file disclosure (Exposure of Sensitive Information) via request smuggling.

  • CVE-2020-10976HigApr 8, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget.

  • CVE-2020-10954HigMar 27, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab through 12.9 is affected by a potential DoS in repository archive download.

  • CVE-2020-10953HigMar 27, 2020
    risk 0.49cvss 7.5epss 0.02

    In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.

  • CVE-2020-10073HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page.

  • CVE-2020-10089HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,

  • CVE-2020-10087HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.

  • CVE-2019-13121HigMar 10, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.

  • CVE-2019-13003HigMar 10, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Uncontrolled Resource Consumption.

  • CVE-2019-12446HigMar 10, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.

  • CVE-2019-12441HigMar 10, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.

  • CVE-2020-8795HigFeb 17, 2020
    risk 0.49cvss 7.5epss 0.01

    In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

  • CVE-2020-6833HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.

  • CVE-2020-7978HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.

  • CVE-2020-7972HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).

  • CVE-2020-7969HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.

  • CVE-2020-7968HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.

  • CVE-2020-7966HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.02

    GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.

  • CVE-2019-5472HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.02

    An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.

  • CVE-2019-5470HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.02

    An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.

  • CVE-2019-15590HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.01

    An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration

  • CVE-2019-15583HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.01

    An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed…

  • CVE-2019-19629HigJan 5, 2020
    risk 0.49cvss 7.5epss 0.01

    In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.

  • CVE-2018-20494HigDec 30, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

  • CVE-2019-15576HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.02

    An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

  • CVE-2019-15575HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.02

    A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

  • CVE-2019-18455HigNov 26, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries. It has a large or infinite loop.

  • CVE-2019-18460HigNov 26, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.

  • CVE-2019-15729HigSep 17, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information about the last pipeline that ran for a merge request.

  • CVE-2019-15736HigSep 16, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Under certain circumstances, CI pipelines could potentially be used in a denial of service attack.

  • CVE-2019-15730HigSep 16, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1. The Jira integration contains a SSRF vulnerability as a result of a bypass of the current protection mechanisms against this type of attack, which would allow sending requests to any…

  • CVE-2019-15728HigSep 16, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.

  • CVE-2019-15725HigSep 16, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure of private milestones, labels, and other information.

  • CVE-2019-15722HigSep 16, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressions in GitLab Markdown can exhaust client resources.

Page 6 of 30