Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gitlab gitlab vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2023-4812
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.5.6, all versions starting from 16.6 prior to 16.6.4, all versions starting from 16.7 prior to 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previou...
Gitlab Gitlab 16.7.0
Gitlab Gitlab 16.7.1
Gitlab Gitlab
8.8
CVSSv3
CVE-2023-5356
Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 prior to 16.5.6, all versions starting from 16.6 prior to 16.6.4, all versions starting from 16.7 prior to 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as...
Gitlab Gitlab 16.7.0
Gitlab Gitlab 16.7.1
Gitlab Gitlab
1 Article
5.3
CVSSv3
CVE-2023-6955
An improper access control vulnerability exists in GitLab Remote Development affecting all versions before 16.5.6, 16.6 before 16.6.4 and 16.7 before 16.7.2. This condition allows an malicious user to create a workspace in one group that is associated with an agent from another g...
Gitlab Gitlab 16.7.0
Gitlab Gitlab 16.7.1
Gitlab Gitlab
7.5
CVSSv3
CVE-2023-7028
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 before 16.1.6, 16.2 before 16.2.9, 16.3 before 16.3.7, 16.4 before 16.4.5, 16.5 before 16.5.6, 16.6 before 16.6.4, and 16.7 before 16.7.2 in which user account password reset emails could be delivered t...
Gitlab Gitlab
16 Github repositories
3 Articles
5.3
CVSSv3
CVE-2023-2030
An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 before 16.5.6, 16.6 before 16.6.4, and 16.7 before 16.7.2 in which an attacker could potentially modify the metadata of signed commits.
Gitlab Gitlab 16.7.0
Gitlab Gitlab 16.7.1
Gitlab Gitlab
5.7
CVSSv3
CVE-2023-6944
A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access...
Redhat Red Hat Developer Hub
Linuxfoundation Backstage
8.8
CVSSv3
CVE-2023-3907
A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 before 16.4.4, 16.5 before 16.5.4, and 16.6 before 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner
Gitlab Gitlab
8.1
CVSSv3
CVE-2023-6680
An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 before 16.4.4, 16.5 before 16.5.4, and 16.6 before 16.6.2 allows an malicious user to authenticate as another user given their public key if they use Smartcard authe...
Gitlab Gitlab
6.5
CVSSv3
CVE-2023-6051
An issue has been discovered in GitLab CE/EE affecting all versions prior to 16.4.4, all versions starting from 16.5 prior to 16.5.4, all versions starting from 16.6 prior to 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a spe...
Gitlab Gitlab
7.5
CVSSv3
CVE-2023-3904
An issue has been discovered in GitLab EE affecting all versions starting prior to 16.4.4, all versions starting from 16.5 prior to 16.5.4, all versions starting from 16.6 prior to 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in th...
Gitlab Gitlab
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
HTML injection
CVE-2024-35894
SQL
CVE-2024-5105
CVE-2014-100005
CVE-2024-35895
unauthorized
CVE-2024-22120
CVE-2024-35890
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »