Skip to main content

Vendor archive

gitlab CVEs

Beta · best-effort

1,422 CVEs tagged to vendor gitlab57 Critical, 295 High, 889 Medium, 180 Low, 1 Unrated.

CVE-2020-13321

Published Sep 30, 2020

A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added.

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13320

Published Sep 30, 2020

An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13319

Published Sep 30, 2020

An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13296

Published Sep 30, 2020

An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13308

Published Sep 15, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by be…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-13307

Published Sep 15, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allow…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-13303

Published Sep 15, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private reposit…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13315

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not restricting the amount of results one could request, potenti…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-13310

Published Sep 14, 2020

A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the gitlab-runner process crash by sending malformed queries, re…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13309

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13306

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abused to perform denial of service attacks due to the lack of…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-13305

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not invalidating project invitation link upon removing a user from a project.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-13304

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-13302

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a maliciou…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-13301

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standalone vulnerability page.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13298

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13297

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. When 2 factor authentication was enabled for groups, a malicious user could bypass that restri…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-13317

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the GraphQL api allowed a maintainer to delete a repository.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13314

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Omniauth endpoint allowed a malicious user to submit content to be displayed back to th…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-13313

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authoriza…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13312

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13311

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functiona…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13318

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13316

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13300

Published Sep 14, 2020

GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort
Showing 1,001-1,025 of 1,422 CVEsPage 41 of 57