Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gitlab vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-0120
An issue has been discovered in GitLab affecting all versions starting from 10.0 prior to 16.1.5, all versions starting from 16.2 prior to 16.2.5, all versions starting from 16.3 prior to 16.3.1. Due to improper permission validation it was possible to edit labels description by ...
Gitlab Gitlab 16.3.0
Gitlab Gitlab
NA
CVE-2022-2326
An issue has been discovered in GitLab CE/EE affecting all versions prior to 15.0.5, all versions starting from 15.1 prior to 15.1.4, all versions starting from 15.2 prior to 15.2.1. It may be possible to gain access to a private project through an email invite by using other use...
Gitlab Gitlab
Gitlab Gitlab 15.2
NA
CVE-2022-2456
An issue has been discovered in GitLab CE/EE affecting all versions prior to 15.0.5, all versions starting from 15.1 prior to 15.1.4, all versions starting from 15.2 prior to 15.2.1. It may be possible for malicious group or project maintainers to change their corresponding group...
Gitlab Gitlab
Gitlab Gitlab 15.2
3.5
CVSSv2
CVE-2022-2227
Improper access control in the runner jobs API in GitLab CE/EE affecting all versions before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions
Gitlab Gitlab 15.1.0
Gitlab Gitlab
4
CVSSv2
CVE-2022-2228
Information exposure in GitLab EE affecting all versions from 12.0 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner ...
Gitlab Gitlab 15.1.0
Gitlab Gitlab
5
CVSSv2
CVE-2022-2229
An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1 allows an malicious user to extract the value of an unprotected variable they know the name of in public projects or private projects they...
Gitlab Gitlab 15.1.0
Gitlab Gitlab
3.5
CVSSv2
CVE-2022-2230
A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1, allows an malicious user to execute arbitrary JavaScript code in GitLab on a victim's behalf.
Gitlab Gitlab 15.1.0
Gitlab Gitlab
3.5
CVSSv2
CVE-2022-2235
Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1 allows an malicious user to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link
Gitlab Gitlab 15.1.0
Gitlab Gitlab
NA
CVE-2022-3513
An issue has been discovered in GitLab affecting all versions starting from 12.8 prior to 15.8.5, all versions starting from 15.9 prior to 15.9.4, all versions starting from 15.10 prior to 15.10.1. A specially crafted payload could lead to a reflected XSS on the client side which...
Gitlab Gitlab 15.10.0
Gitlab Gitlab
NA
CVE-2024-1525
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.7.6, all versions starting from 16.8 prior to 16.8.3, all versions starting from 16.9 prior to 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their pas...
Gitlab Gitlab 16.9.0
Gitlab Gitlab
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
CVE-2006-4304
wireless
CVE-2023-23022
local file inclusion
CVE-2024-27058
CVE-2024-33820
open redirect
CVE-2024-27079
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »