Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gitlab gitlab 15.2 vulnerabilities and exploits
(subscribe to this query)
6.4
CVSSv3
CVE-2022-2497
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 prior to 15.0.5, all versions starting from 15.1 prior to 15.1.4, all versions starting from 15.2 prior to 15.2.1. A malicious developer could exfiltrate an integration's access token by m...
Gitlab Gitlab
Gitlab Gitlab 15.2
7.5
CVSSv3
CVE-2022-2498
An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 before 15.0.5, 15.1 before 15.1.4, and 15.2 before 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.
Gitlab Gitlab
Gitlab Gitlab 15.2
4.3
CVSSv3
CVE-2022-2499
An issue has been discovered in GitLab EE affecting all versions starting from 13.10 prior to 15.0.5, all versions starting from 15.1 prior to 15.1.4, all versions starting from 15.2 prior to 15.2.1. GitLab's Jira integration has an insecure direct object reference vulnerabi...
Gitlab Gitlab
Gitlab Gitlab 15.2
5.4
CVSSv3
CVE-2022-2500
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1. A stored XSS flaw in job error messages allows malicious users to perform arbitrary actions on behalf of victims at client side...
Gitlab Gitlab
Gitlab Gitlab 15.2
7.5
CVSSv3
CVE-2022-2501
An improper access control issue in GitLab EE affecting all versions from 12.0 before 15.0.5, 15.1 before 15.1.4, and 15.2 before 15.2.1 allows an malicious user to bypass IP allow-listing and download artifacts. This attack only bypasses IP allow-listing, proper permissions are ...
Gitlab Gitlab
Gitlab Gitlab 15.2
6.5
CVSSv3
CVE-2022-2512
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 prior to 15.0.5, all versions starting from 15.1 prior to 15.1.4, all versions starting from 15.2 prior to 15.2.1. Membership changes are not reflected in TODO for confidential notes, allowing ...
Gitlab Gitlab
Gitlab Gitlab 15.2
2.7
CVSSv3
CVE-2022-2456
An issue has been discovered in GitLab CE/EE affecting all versions prior to 15.0.5, all versions starting from 15.1 prior to 15.1.4, all versions starting from 15.2 prior to 15.2.1. It may be possible for malicious group or project maintainers to change their corresponding group...
Gitlab Gitlab
Gitlab Gitlab 15.2
2.7
CVSSv3
CVE-2022-2459
An issue has been discovered in GitLab EE affecting all versions prior to 15.0.5, all versions starting from 15.1 prior to 15.1.4, all versions starting from 15.2 prior to 15.2.1. It may be possible for email invited members to join a project even after the Group Owner has enable...
Gitlab Gitlab
Gitlab Gitlab 15.2
3.8
CVSSv3
CVE-2022-2307
A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 prior to 15.0.5, all versions starting from 15.1 prior to 15.1.4, all versions starting from 15.2 prior to 15.2.1 allows a malicious Group Owner to retain a usable Group Access Token even after ...
Gitlab Gitlab
Gitlab Gitlab 15.2
4.5
CVSSv3
CVE-2022-2417
Insufficient validation in GitLab CE/EE affecting all versions from 12.10 before 15.0.5, 15.1 before 15.1.4, and 15.2 before 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could be abuse...
Gitlab Gitlab
Gitlab Gitlab 15.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48654
CVE-2024-2757
authentication bypass
CVE-2024-3194
CVE-2024-33640
CVE-2024-21111
dos
insecure direct object reference
CVE-2024-21345
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »