Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gitlab gitlab vulnerabilities and exploits
(subscribe to this query)
5.8
CVSSv2
CVE-2022-2250
An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1, allows an malicious user to redirect users to an arbitrary location if they trust the URL.
Gitlab Gitlab 15.1.0
Gitlab Gitlab
NA
CVE-2023-4700
An authorization issue affecting GitLab EE affecting all versions from 14.7 before 16.3.6, 16.4 before 16.4.2, and 16.5 before 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.
Gitlab Gitlab
Gitlab Gitlab 16.5.0
NA
CVE-2023-4018
An issue has been discovered in GitLab affecting all versions starting from 16.2 prior to 16.2.5, all versions starting from 16.3 prior to 16.3.1. Due to improper permission validation it was possible to create model experiments in public projects.
Gitlab Gitlab 16.3.0
Gitlab Gitlab
NA
CVE-2023-5825
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 prior to 16.3.6, all versions starting from 16.4 prior to 16.4.2, all versions starting from 16.5 prior to 16.5.1. A low-privileged attacker can point a CI/CD Component to an incorrect path and...
Gitlab Gitlab
Gitlab Gitlab 16.5.0
NA
CVE-2023-5831
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 16.3.6, all versions starting from 16.4 prior to 16.4.2, and all versions starting from 16.5.0 prior to 16.5.1 which have the `super_sidebar_logged_out` feature flag enabled. Affected ...
Gitlab Gitlab
Gitlab Gitlab 16.5.0
NA
CVE-2023-5933
An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.
Gitlab Gitlab 16.8.0
Gitlab Gitlab
NA
CVE-2023-5963
An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 before 16.4.2 and 16.5 before 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.
Gitlab Gitlab
Gitlab Gitlab 16.5.0
NA
CVE-2023-5995
An issue has been discovered in GitLab EE affecting all versions starting from 16.2 prior to 16.4.3, all versions starting from 16.5 prior to 16.5.3, all versions starting from 16.6 prior to 16.6.1. It was possible for an malicious user to abuse the policy bot to gain access to i...
Gitlab Gitlab
Gitlab Gitlab 16.6.0
NA
CVE-2023-3509
An issue has been discovered in GitLab affecting all versions prior to 16.7.6, all versions starting from 16.8 prior to 16.8.3, all versions starting from 16.9 prior to 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible ...
Gitlab Gitlab 16.9.0
Gitlab Gitlab
NA
CVE-2023-5106
An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 before 16.2.8, 16.3.0 before 16.3.5, and 16.4.0 before 16.4.1 that could allow an malicious user to impersonate users in CI pipelines through direct transfer group imports.
Gitlab Gitlab
Gitlab Gitlab 16.4.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »