Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gitlab vulnerabilities and exploits
(subscribe to this query)
356
VMScore
CVE-2022-2228
Information exposure in GitLab EE affecting all versions from 12.0 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner ...
Gitlab Gitlab 15.1.0
Gitlab Gitlab
445
VMScore
CVE-2022-2229
An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1 allows an malicious user to extract the value of an unprotected variable they know the name of in public projects or private projects they...
Gitlab Gitlab 15.1.0
Gitlab Gitlab
312
VMScore
CVE-2022-2230
A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1, allows an malicious user to execute arbitrary JavaScript code in GitLab on a victim's behalf.
Gitlab Gitlab 15.1.0
Gitlab Gitlab
312
VMScore
CVE-2022-2235
Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1 allows an malicious user to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link
Gitlab Gitlab 15.1.0
Gitlab Gitlab
356
VMScore
CVE-2022-2243
An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.
Gitlab Gitlab 15.1.0
Gitlab Gitlab
356
VMScore
CVE-2022-2244
An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1, allows project memebers with reporter role to manage issues in project's error tracking feature.
Gitlab Gitlab 15.1.0
Gitlab Gitlab
516
VMScore
CVE-2022-2250
An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1, allows an malicious user to redirect users to an arbitrary location if they trust the URL.
Gitlab Gitlab 15.1.0
Gitlab Gitlab
NA
CVE-2023-4378
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.1.5, all versions starting from 16.2 prior to 16.2.5, all versions starting from 16.3 prior to 16.3.1. A malicious Maintainer can, under specific circumstances, leak the sentry toke...
Gitlab Gitlab 16.3.0
Gitlab Gitlab
NA
CVE-2023-4379
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.2.8, 16.3 before 16.3.5, and 16.4 before 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.
Gitlab Gitlab
Gitlab Gitlab 16.4.0
NA
CVE-2023-0989
An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 before 16.2.8, 16.3 before 16.3.5, and 16.4 before 16.4.1 allows an malicious user to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configu...
Gitlab Gitlab
Gitlab Gitlab 16.4.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5324
path traversal
CVE-2024-4743
CVE-2024-5184
TCP
CVE-2024-27822
code injection
CVE-2024-28995
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »