Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gitlab vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-4143
An issue has been discovered in GitLab affecting all versions starting from 15.7 prior to 15.8.5, from 15.9 prior to 15.9.4, and from 15.10 prior to 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization
Gitlab Gitlab 15.10.0
Gitlab Gitlab
5
CVSSv2
CVE-2022-2270
An issue has been discovered in GitLab affecting all versions starting from 12.4 prior to 14.10.5, all versions starting from 15.0 prior to 15.0.4, all versions starting from 15.1 prior to 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.
Gitlab Gitlab 15.1.0
Gitlab Gitlab
4.3
CVSSv2
CVE-2022-2281
An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.
Gitlab Gitlab 15.1.0
Gitlab Gitlab
NA
CVE-2022-2303
An issue has been discovered in GitLab CE/EE affecting all versions prior to 15.0.5, all versions starting from 15.1 prior to 15.1.4, all versions starting from 15.2 prior to 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by usin...
Gitlab Gitlab
Gitlab Gitlab 15.2
5.8
CVSSv2
CVE-2022-2250
An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1, allows an malicious user to redirect users to an arbitrary location if they trust the URL.
Gitlab Gitlab 15.1.0
Gitlab Gitlab
3.5
CVSSv2
CVE-2022-1416
Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and all versions from 14.10.0 prior to 14.10.1 allows for rendering of attacker controlled HTML tags and C...
Gitlab Gitlab 14.10.0
Gitlab Gitlab
4.3
CVSSv2
CVE-2022-1426
An issue has been discovered in GitLab affecting all versions starting from 12.6 prior to 14.8.6, all versions starting from 14.9 prior to 14.9.4, all versions starting from 14.10 prior to 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of inf...
Gitlab Gitlab 14.10.0
Gitlab Gitlab
4.3
CVSSv2
CVE-2022-1433
An issue has been discovered in GitLab affecting all versions starting from 14.4 prior to 14.8.6, all versions starting from 14.9 prior to 14.9.4, all versions starting from 14.10 prior to 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previous...
Gitlab Gitlab 14.10.0
Gitlab Gitlab
4.3
CVSSv2
CVE-2021-22200
An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an internal repository through a public project fork as an anonymous user.
Gitlab Gitlab
Gitlab Gitlab 13.10.0
NA
CVE-2022-3513
An issue has been discovered in GitLab affecting all versions starting from 12.8 prior to 15.8.5, all versions starting from 15.9 prior to 15.9.4, all versions starting from 15.10 prior to 15.10.1. A specially crafted payload could lead to a reflected XSS on the client side which...
Gitlab Gitlab 15.10.0
Gitlab Gitlab
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
7
8
9
10
NEXT »