Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gitlab gitlab vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2022-1416
Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and all versions from 14.10.0 prior to 14.10.1 allows for rendering of attacker controlled HTML tags and C...
Gitlab Gitlab 14.10.0
Gitlab Gitlab
4
CVSSv2
CVE-2022-1417
Improper access control in GitLab CE/EE affecting all versions starting from 8.12 prior to 14.8.6, all versions starting from 14.9 prior to 14.9.4, and all versions starting from 14.10 prior to 14.10.1 allows non-project members to access contents of Project Members-only Wikis vi...
Gitlab Gitlab 14.10.0
Gitlab Gitlab
6.5
CVSSv2
CVE-2022-1423
Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and all versions from 14.10.0 prior to 14.10.1 allows a malicious actor with Developer privileges to perform ...
Gitlab Gitlab 14.10.0
Gitlab Gitlab
4.3
CVSSv2
CVE-2022-1426
An issue has been discovered in GitLab affecting all versions starting from 12.6 prior to 14.8.6, all versions starting from 14.9 prior to 14.9.4, all versions starting from 14.10 prior to 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of inf...
Gitlab Gitlab 14.10.0
Gitlab Gitlab
4
CVSSv2
CVE-2022-1428
An issue has been discovered in GitLab affecting all versions prior to 14.8.6, all versions starting from 14.9 prior to 14.9.4, all versions starting from 14.10 prior to 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted ...
Gitlab Gitlab 14.10.0
Gitlab Gitlab
5
CVSSv2
CVE-2022-1431
An issue has been discovered in GitLab affecting all versions starting from 12.10 prior to 14.8.6, all versions starting from 14.9 prior to 14.9.4, all versions starting from 14.10 prior to 14.10.1. GitLab was not correctly handling malicious requests to the PyPi API endpoint all...
Gitlab Gitlab 14.10.0
Gitlab Gitlab
4.3
CVSSv2
CVE-2022-1433
An issue has been discovered in GitLab affecting all versions starting from 14.4 prior to 14.8.6, all versions starting from 14.9 prior to 14.9.4, all versions starting from 14.10 prior to 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previous...
Gitlab Gitlab 14.10.0
Gitlab Gitlab
4
CVSSv2
CVE-2022-1460
An issue has been discovered in GitLab affecting all versions starting from 9.2 prior to 14.8.6, all versions starting from 14.9 prior to 14.9.4, all versions starting from 14.10 prior to 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a ...
Gitlab Gitlab 14.10.0
Gitlab Gitlab
NA
CVE-2023-4658
An issue has been discovered in GitLab EE affecting all versions starting from 8.13 prior to 16.4.3, all versions starting from 16.5 prior to 16.5.3, all versions starting from 16.6 prior to 16.6.1. It was possible for an malicious user to abuse the `Allowed to merge` permission ...
Gitlab Gitlab
Gitlab Gitlab 16.6.0
NA
CVE-2022-3572
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 before 15.3.5, 15.4 before 15.4.4, and 15.5 before 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that...
Gitlab Gitlab 15.6.0
Gitlab Gitlab
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »