Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gitlab gitlab vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2022-1954
A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1 allows an malicious user to make a GitLab instance inaccessible via specially crafted web server response headers
Gitlab Gitlab 15.1.0
Gitlab Gitlab
3.5
CVSSv2
CVE-2022-1981
An issue has been discovered in GitLab EE affecting all versions starting from 12.2 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that allow-list may be bypassed if ...
Gitlab Gitlab 15.1.0
Gitlab Gitlab
5
CVSSv2
CVE-2022-2270
An issue has been discovered in GitLab affecting all versions starting from 12.4 prior to 14.10.5, all versions starting from 15.0 prior to 15.0.4, all versions starting from 15.1 prior to 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.
Gitlab Gitlab 15.1.0
Gitlab Gitlab
4.3
CVSSv2
CVE-2022-2281
An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.
Gitlab Gitlab 15.1.0
Gitlab Gitlab
NA
CVE-2018-17449
An issue exists in GitLab Community and Enterprise Edition prior to 11.1.7, 11.2.x prior to 11.2.4, and 11.3.x prior to 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure direct object reference.
Gitlab Gitlab
Gitlab Gitlab 11.3.0
NA
CVE-2018-17450
An issue exists in GitLab Community and Enterprise Edition prior to 11.1.7, 11.2.x prior to 11.2.4, and 11.3.x prior to 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.
Gitlab Gitlab
Gitlab Gitlab 11.3.0
NA
CVE-2018-17452
An issue exists in GitLab Community and Enterprise Edition prior to 11.1.7, 11.2.x prior to 11.2.4, and 11.3.x prior to 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.
Gitlab Gitlab
Gitlab Gitlab 11.3.0
NA
CVE-2018-17453
An issue exists in GitLab Community and Enterprise Edition prior to 11.1.7, 11.2.x prior to 11.2.4, and 11.3.x prior to 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.
Gitlab Gitlab
Gitlab Gitlab 11.3.0
NA
CVE-2018-17454
An issue exists in GitLab Community and Enterprise Edition prior to 11.1.7, 11.2.x prior to 11.2.4, and 11.3.x prior to 11.3.1. There is stored XSS on the issue details screen.
Gitlab Gitlab
Gitlab Gitlab 11.3.0
NA
CVE-2018-17455
An issue exists in GitLab Enterprise Edition prior to 11.1.7, 11.2.x prior to 11.2.4, and 11.3.x prior to 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge re...
Gitlab Gitlab
Gitlab Gitlab 11.3.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33228
CVE-2024-20361
log injection
bypass
CVE-2024-4985
CVE-2024-35223
CVE-2024-29849
CVE-2024-31893
IMAP
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »