Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gitlab gitlab vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2020-13264
Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later up to and including 13.0.1 allows other group maintainers to view Kubernetes cluster token
Gitlab Gitlab
Gitlab Gitlab 13.0.0
7.5
CVSSv3
CVE-2020-13274
A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions up to and including 13.0.1
Gitlab Gitlab
Gitlab Gitlab 13.0.0
8.1
CVSSv3
CVE-2020-13275
A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later up to and including 13.0.1
Gitlab Gitlab
Gitlab Gitlab 13.0.0
4.3
CVSSv3
CVE-2020-13276
User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions up to and including 13.0.1
Gitlab Gitlab
Gitlab Gitlab 13.0.0
7.5
CVSSv3
CVE-2023-5226
An issue has been discovered in GitLab affecting all versions prior to 16.4.3, all versions starting from 16.5 prior to 16.5.3, all versions starting from 16.6 prior to 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafte...
Gitlab Gitlab
Gitlab Gitlab 16.6.0
6.5
CVSSv3
CVE-2022-1936
Incorrect authorization in GitLab EE affecting all versions from 12.0 prior to 14.9.5, all versions starting from 14.10 prior to 14.10.4, all versions starting from 15.0 prior to 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from an...
Gitlab Gitlab
Gitlab Gitlab 15.0.0
7.1
CVSSv3
CVE-2022-1944
When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 before 14.9.5, 14.10 before 14.10.4, and 15.0 before 15.0.1 allows users with the Developer role to open terminals on other Developers' run...
Gitlab Gitlab
Gitlab Gitlab 15.0.0
5.3
CVSSv3
CVE-2022-1963
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 prior to 14.10.5, all versions starting from 15.0 prior to 15.0.4, all versions starting from 15.1 prior to 15.1.1. GitLab reveals if a user has enabled two-factor authentication on their accou...
Gitlab Gitlab 15.1.0
Gitlab Gitlab
4.3
CVSSv3
CVE-2023-3115
An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 before 16.2.8, 16.3 before 16.3.5, and 16.4 before 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project...
Gitlab Gitlab
Gitlab Gitlab 16.4.0
5.5
CVSSv3
CVE-2022-4054
An issue has been discovered in GitLab affecting all versions starting from 9.3 prior to 15.4.6, all versions starting from 15.5 prior to 15.5.5, all versions starting from 15.6 prior to 15.6.1. It was possible for a project maintainer to leak a webhook secret token by changing t...
Gitlab Gitlab 15.6.0
Gitlab Gitlab
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22120
CVE-2024-35921
CVE-2024-35874
brute force
CVE-2024-36080
unprivileged
CVE-2024-35917
IDOR
CVE-2024-4947
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »