Skip to main content

Vendor archive

gitlab CVEs

Beta · best-effort

1,422 CVEs tagged to vendor gitlab57 Critical, 295 High, 889 Medium, 180 Low, 1 Unrated.

CVE-2020-13327

Published Oct 22, 2020

An issue has been discovered in GitLab Runner affecting all versions starting from 13.4.0 before 13.4.2, all versions starting from 13.3.0 before 13.3.7, all versions starting fro…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13341

Published Oct 12, 2020

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Insufficient permission check allows attacker with developer role to perform var…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13344

Published Oct 8, 2020

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are stored in plain-text in Redis which allows attacker with Redis…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13340

Published Oct 8, 2020

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13339

Published Oct 8, 2020

An issue has been discovered in GitLab affecting all versions before 13.2.10, 13.3.7 and 13.4.2: XSS in SVG File Preview. Overall impact is limited due to the current user only be…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13342

Published Oct 7, 2020

An issue has been discovered in GitLab affecting versions prior to 13.2.10, 13.3.7 and 13.4.2: Lack of Rate Limiting at Re-Sending Confirmation Email

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-13347

Published Oct 7, 2020

A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Windows system with a docker exec…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-13346

Published Oct 7, 2020

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13335

Published Oct 7, 2020

Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13334

Published Oct 7, 2020

In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentiality attribute of issue via mu…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13345

Published Oct 6, 2020

An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13343

Published Oct 6, 2020

An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13333

Published Oct 6, 2020

A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a link from a release had a regex check which caused exponential…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13338

Published Oct 2, 2020

An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13337

Published Oct 2, 2020

An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload to be added as a group name.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13336

Published Sep 30, 2020

An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored XSS by in the error tracking feature.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13331

Published Sep 30, 2020

An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13330

Published Sep 30, 2020

An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS in import the Bitbucket project feature.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13329

Published Sep 30, 2020

An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the blob view feature.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13328

Published Sep 30, 2020

An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. GitLab was vulnerable to a stored XSS by using the PyPi files API.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13326

Published Sep 30, 2020

A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the restriction for Github project import could be bypassed.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13325

Published Sep 30, 2020

A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting the characters properly, potentially resulting in a denial…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13324

Published Sep 30, 2020

A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13323

Published Sep 30, 2020

A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be read via Todos

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13322

Published Sep 30, 2020

A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthorized user can create and delete deploy tokens.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 976-1,000 of 1,422 CVEsPage 40 of 57