Skip to main content

Vendor archive

gitlab CVEs

Beta · best-effort

1,422 CVEs tagged to vendor gitlab57 Critical, 295 High, 889 Medium, 180 Low, 1 Unrated.

CVE-2020-13299

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13289

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13287

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13284

Published Sep 14, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13286

Published Aug 13, 2020

For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13281

Published Aug 13, 2020

For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13285

Published Aug 13, 2020

For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13283

Published Aug 13, 2020

For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13282

Published Aug 13, 2020

For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-13280

Published Aug 13, 2020

For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13291

Published Aug 12, 2020

In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13290

Published Aug 12, 2020

In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13288

Published Aug 12, 2020

In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13295

Published Aug 10, 2020

For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13294

Published Aug 10, 2020

In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13293

Published Aug 10, 2020

In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13292

Published Aug 10, 2020

In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15525

Published Jul 7, 2020

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13264

Published Jun 19, 2020

Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13263

Published Jun 19, 2020

An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13261

Published Jun 19, 2020

Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13276

Published Jun 19, 2020

User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13275

Published Jun 19, 2020

A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13274

Published Jun 19, 2020

A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,026-1,050 of 1,422 CVEsPage 42 of 57