Skip to main content

Vendor archive

gitlab CVEs

Beta · best-effort

1,422 CVEs tagged to vendor gitlab57 Critical, 295 High, 889 Medium, 180 Low, 1 Unrated.

CVE-2021-22166

Published Jan 15, 2021

An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26414

Published Jan 15, 2021

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic gro…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26411

Published Dec 11, 2020

A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query n…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26417

Published Dec 11, 2020

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=1…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26416

Published Dec 11, 2020

Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26415

Published Dec 11, 2020

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26413

Published Dec 11, 2020

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly v…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26412

Published Dec 11, 2020

Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-26408

Published Dec 11, 2020

A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited inf…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13357

Published Dec 11, 2020

An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26409

Published Dec 11, 2020

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26407

Published Dec 10, 2020

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other use…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13359

Published Nov 19, 2020

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, by…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13356

Published Nov 19, 2020

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain sp…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13355

Published Nov 19, 2020

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26405

Published Nov 17, 2020

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13349

Published Nov 17, 2020

An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted in the Advanced Search feature susceptibl…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13348

Published Nov 17, 2020

An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS fi…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13351

Published Nov 17, 2020

Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13350

Published Nov 17, 2020

CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners. Affected version…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-26406

Published Nov 17, 2020

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of publ…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13358

Published Nov 17, 2020

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13354

Published Nov 17, 2020

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13353

Published Nov 17, 2020

When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-13352

Published Nov 17, 2020

Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions are: >=10.2, <13.3.9,>=13.4,…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 951-975 of 1,422 CVEsPage 39 of 57