Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gitlab gitlab vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2020-13276
User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions up to and including 13.0.1
Gitlab Gitlab
Gitlab Gitlab 13.0.0
4.3
CVSSv3
CVE-2023-5198
An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 prior to 16.3.5, and all versions starting from 16.4 prior to 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.
Gitlab Gitlab
Gitlab Gitlab 16.4.0
8.8
CVSSv3
CVE-2023-5207
A vulnerability exists in GitLab CE and EE affecting all versions starting 16.0 before 16.2.8, 16.3 before 16.3.5, and 16.4 before 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.
Gitlab Gitlab
Gitlab Gitlab 16.4.0
8.8
CVSSv3
CVE-2022-2185
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code executio...
Gitlab Gitlab 15.1.0
Gitlab Gitlab
3 Github repositories
6.1
CVSSv3
CVE-2022-1433
An issue has been discovered in GitLab affecting all versions starting from 14.4 prior to 14.8.6, all versions starting from 14.9 prior to 14.9.4, all versions starting from 14.10 prior to 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previous...
Gitlab Gitlab 14.10.0
Gitlab Gitlab
5.4
CVSSv3
CVE-2022-2904
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting from 15.2 prior to 15.2.5, all versions starting from 15.3 prior to 15.3.4, all versions starting from 15.4 prior to 15.4.1 It was possible to exploit a vulnerability in the external ...
Gitlab Gitlab
Gitlab Gitlab 15.4
6.5
CVSSv3
CVE-2021-39872
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
Gitlab Gitlab 4.3.0
Gitlab Gitlab
4.3
CVSSv3
CVE-2021-39883
Improper authorization checks in all versions of GitLab EE starting from 13.11 prior to 14.1.7, all versions starting from 14.2 prior to 14.2.5, and all versions starting from 14.3 prior to 14.3.1 allows subgroup members to see epics from all parent subgroups.
Gitlab Gitlab
Gitlab Gitlab 14.3.0
5.4
CVSSv3
CVE-2021-39885
A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 prior to 14.1.7, all versions starting from 14.2 prior to 14.2.5, and all versions starting from 14.3 prior to 14.3.1 allows an malicious user to execute arbitrary JavaScript code on the v...
Gitlab Gitlab
Gitlab Gitlab 14.3.0
7.5
CVSSv3
CVE-2023-5226
An issue has been discovered in GitLab affecting all versions prior to 16.4.3, all versions starting from 16.5 prior to 16.5.3, all versions starting from 16.6 prior to 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafte...
Gitlab Gitlab
Gitlab Gitlab 16.6.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-3400
deserialization
CVE-2024-21788
CVE-2023-42433
CVE-2024-21841
CVE-2024-22095
local file inclusion
memory leak
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »