Skip to main content

Vendor archive

gitlab CVEs

Beta · best-effort

1,422 CVEs tagged to vendor gitlab57 Critical, 295 High, 889 Medium, 180 Low, 1 Unrated.

CVE-2021-22198

Published Apr 2, 2021

An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22197

Published Apr 2, 2021

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 where an infinite loop exist when an authenticated user with specific rights access a MR hav…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-22196

Published Apr 2, 2021

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in merge request via a specificall…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22177

Published Apr 1, 2021

Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22194

Published Mar 26, 2021

In all versions of GitLab, marshalled session keys were being stored in Redis.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22184

Published Mar 26, 2021

An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22180

Published Mar 26, 2021

An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22172

Published Mar 26, 2021

Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22169

Published Mar 24, 2021

An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22193

Published Mar 24, 2021

An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specific name for private project.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-22192

Published Mar 24, 2021

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server.

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-22186

Published Mar 24, 2021

An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22185

Published Mar 24, 2021

Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted commit to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22179

Published Mar 24, 2021

A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22178

Published Mar 24, 2021

An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22176

Published Mar 24, 2021

An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge reque…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22189

Published Mar 4, 2021

Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in auth…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22183

Published Mar 4, 2021

An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS in the epics page, which could be exploited with user inter…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22188

Published Mar 3, 2021

An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorised user via branch logs.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22182

Published Mar 3, 2021

An issue has been discovered in GitLab affecting all versions starting with 13.7. GitLab was vulnerable to a stored XSS in merge request.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-22187

Published Mar 2, 2021

An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22171

Published Jan 15, 2021

Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22168

Published Jan 15, 2021

A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22167

Published Jan 15, 2021

An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 926-950 of 1,422 CVEsPage 38 of 57