Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gitlab gitlab vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2022-2904
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting from 15.2 prior to 15.2.5, all versions starting from 15.3 prior to 15.3.4, all versions starting from 15.4 prior to 15.4.1 It was possible to exploit a vulnerability in the external ...
Gitlab Gitlab
Gitlab Gitlab 15.4
4.3
CVSSv3
CVE-2022-4343
An issue has been discovered in GitLab EE affecting all versions starting from 13.12 prior to 16.1.5, all versions starting from 16.2 prior to 16.2.5, all versions starting from 16.3 prior to 16.3.1 in which a project member can leak credentials stored in site profile.
Gitlab Gitlab 16.3.0
Gitlab Gitlab
3.1
CVSSv3
CVE-2023-4658
An issue has been discovered in GitLab EE affecting all versions starting from 8.13 prior to 16.4.3, all versions starting from 16.5 prior to 16.5.3, all versions starting from 16.6 prior to 16.6.1. It was possible for an malicious user to abuse the `Allowed to merge` permission ...
Gitlab Gitlab
Gitlab Gitlab 16.6.0
4.5
CVSSv3
CVE-2022-2417
Insufficient validation in GitLab CE/EE affecting all versions from 12.10 before 15.0.5, 15.1 before 15.1.4, and 15.2 before 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could be abuse...
Gitlab Gitlab
Gitlab Gitlab 15.2
6.1
CVSSv3
CVE-2020-13262
Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later up to and including 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link
Gitlab Gitlab
Gitlab Gitlab 13.0.0
5.3
CVSSv3
CVE-2020-13265
User email verification bypass in GitLab CE/EE 12.5 and later up to and including 13.0.1 allows user to bypass email verification
Gitlab Gitlab
Gitlab Gitlab 13.0.0
8.8
CVSSv3
CVE-2020-13272
OAuth flow missing verification checks CE/EE 12.3 and later up to and including 13.0.1 allows unverified user to use OAuth authorization code flow
Gitlab Gitlab
Gitlab Gitlab 13.0.0
9.9
CVSSv3
CVE-2024-0402
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 16.6.6, 16.7 before 16.7.4, and 16.8 before 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.
Gitlab Gitlab 16.8.0
Gitlab Gitlab
1 Github repository
7.7
CVSSv3
CVE-2024-0410
An authorization bypass vulnerability exists in GitLab affecting versions 15.1 before 16.7.6, 16.8 before 16.8.3, and 16.9 before 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.
Gitlab Gitlab 16.9.0
Gitlab Gitlab
4.3
CVSSv3
CVE-2024-0456
An authorization vulnerability exists in GitLab versions 14.0 before 16.6.6, 16.7 before 16.7.4, and 16.8 before 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project
Gitlab Gitlab 16.8.0
Gitlab Gitlab
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22120
CVE-2024-35921
CVE-2024-35874
brute force
CVE-2024-36080
unprivileged
CVE-2024-35917
IDOR
CVE-2024-4947
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »