Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gitlab vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2023-2182
An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 15.10.5, all versions starting from 15.11 prior to 15.11.1. Under certain conditions when OpenID Connect is enabled on an instance, it may allow users who are marked as 'external...
Gitlab Gitlab 15.11.0
Gitlab Gitlab
5.3
CVSSv3
CVE-2022-2539
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.6 before 15.0.5, 15.1 before 15.1.4, and 15.2 before 15.2.1, allowed a project member to filter issues by contact and organization.
Gitlab Gitlab
Gitlab Gitlab 15.2
2.7
CVSSv3
CVE-2022-2456
An issue has been discovered in GitLab CE/EE affecting all versions prior to 15.0.5, all versions starting from 15.1 prior to 15.1.4, all versions starting from 15.2 prior to 15.2.1. It may be possible for malicious group or project maintainers to change their corresponding group...
Gitlab Gitlab
Gitlab Gitlab 15.2
5.4
CVSSv3
CVE-2022-2500
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1. A stored XSS flaw in job error messages allows malicious users to perform arbitrary actions on behalf of victims at client side...
Gitlab Gitlab
Gitlab Gitlab 15.2
7.5
CVSSv3
CVE-2022-1510
An issue has been discovered in GitLab affecting all versions starting from 13.9 prior to 14.8.6, all versions starting from 14.9 prior to 14.9.4, all versions starting from 14.10 prior to 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline ...
Gitlab Gitlab 14.10.0
Gitlab Gitlab
4.3
CVSSv3
CVE-2022-1545
It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 before 14.8.6, 14.9 before 14.9.4, and 14.10 before 14.10.1 if an unauthorised project member was tagged in the note.
Gitlab Gitlab 14.10.0
Gitlab Gitlab
5.5
CVSSv3
CVE-2022-4054
An issue has been discovered in GitLab affecting all versions starting from 9.3 prior to 15.4.6, all versions starting from 15.5 prior to 15.5.5, all versions starting from 15.6 prior to 15.6.1. It was possible for a project maintainer to leak a webhook secret token by changing t...
Gitlab Gitlab 15.6.0
Gitlab Gitlab
6.1
CVSSv3
CVE-2022-2250
An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1, allows an malicious user to redirect users to an arbitrary location if they trust the URL.
Gitlab Gitlab 15.1.0
Gitlab Gitlab
4.9
CVSSv3
CVE-2022-3740
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.3.5, 15.4 before 15.4.4, and 15.5 before 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries ...
Gitlab Gitlab 15.6.0
Gitlab Gitlab
6.5
CVSSv3
CVE-2023-3205
An issue has been discovered in GitLab affecting all versions starting from 15.11 prior to 16.1.5, all versions starting from 16.2 prior to 16.2.5, all versions starting from 16.3 prior to 16.3.1. An authenticated user could trigger a denial of service when importing or cloning m...
Gitlab Gitlab 16.3.0
Gitlab Gitlab
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
firmware
CVE-2006-4304
CVE-2024-32878
CVE-2024-31502
XSS
CVE-2024-3059
CVE-2024-33692
CVE-2024-3400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »