Lucene search

K

Gitlab Oauth Security Vulnerabilities

cve
cve

CVE-2024-4024

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker with their Bitbucket account credentials may be able to take.....

7.3CVSS

6.1AI Score

0.0004EPSS

2024-04-25 02:15 PM
45
cve
cve

CVE-2022-4037

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth...

8.5CVSS

8.1AI Score

0.004EPSS

2023-01-12 04:15 AM
82
cve
cve

CVE-2022-1162

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over...

9.8CVSS

9.2AI Score

0.296EPSS

2022-04-04 08:15 PM
97
cve
cve

CVE-2021-39881

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and...

3.5CVSS

4AI Score

0.001EPSS

2021-10-05 02:15 PM
32
cve
cve

CVE-2021-22236

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version...

8.8CVSS

8.2AI Score

0.001EPSS

2021-08-25 07:15 PM
24
cve
cve

CVE-2021-22213

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with...

8.8CVSS

6.1AI Score

0.002EPSS

2021-06-08 07:15 PM
21
4
cve
cve

CVE-2020-13312

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific...

9.8CVSS

9AI Score

0.002EPSS

2020-09-14 08:15 PM
23
cve
cve

CVE-2020-13300

GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization...

10CVSS

9.1AI Score

0.002EPSS

2020-09-14 07:15 PM
30
cve
cve

CVE-2020-13292

In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth...

9.6CVSS

9.1AI Score

0.001EPSS

2020-08-10 02:15 PM
31
cve
cve

CVE-2020-13272

OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code...

8.8CVSS

8.6AI Score

0.002EPSS

2020-06-19 10:15 PM
37
cve
cve

CVE-2019-6788

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 3 of 6). For installations using GitHub or Bitbucket OAuth integrations, it is possible to use a covert redirect to obtain the...

7.5CVSS

7.1AI Score

0.002EPSS

2019-09-09 08:15 PM
96
cve
cve

CVE-2019-10372

An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users to a URL outside Jenkins after successful...

6.1CVSS

6.1AI Score

0.001EPSS

2019-08-07 03:15 PM
38
cve
cve

CVE-2019-10371

A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows unauthorized attackers to impersonate another user if they can control the pre-authentication...

7.5CVSS

7.4AI Score

0.002EPSS

2019-08-07 03:15 PM
33
cve
cve

CVE-2018-19574

GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in the OAuth authorization...

5.4CVSS

5.2AI Score

0.001EPSS

2019-07-10 04:15 PM
25
cve
cve

CVE-2019-10117

An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo...

6.1CVSS

6.7AI Score

0.001EPSS

2019-05-16 03:29 PM
27
cve
cve

CVE-2019-10114

An Information Exposure issue (issue 2 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. During the OAuth authentication process, the application attempts to validate a parameter in an insecure way, potentially exposing...

7.5CVSS

7.6AI Score

0.003EPSS

2019-05-16 03:29 PM
25
cve
cve

CVE-2017-0926

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user...

8.8CVSS

7.7AI Score

0.003EPSS

2018-03-21 08:29 PM
31