Lucene search

K

Gitlab Security Vulnerabilities

cve
cve

CVE-2022-3819

An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a malicious users to set emojis on internal notes they don't have access to.

4.3CVSS

4.4AI Score

0.001EPSS

2022-11-10 12:15 AM
37
4
cve
cve

CVE-2022-3820

An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a val...

6.5CVSS

6.1AI Score

0.001EPSS

2023-01-26 09:15 PM
40
cve
cve

CVE-2022-3870

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated users to download user avatars using the victim's user ID, on private ins...

5.3CVSS

4.9AI Score

0.001EPSS

2023-01-12 04:15 AM
59
cve
cve

CVE-2022-3902

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to unmask webhook secret tokens by reviewing the logs after testing w...

6.4CVSS

6AI Score

0.001EPSS

2023-01-26 09:16 PM
40
cve
cve

CVE-2022-4007

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf ...

6.1CVSS

5.8AI Score

0.001EPSS

2023-03-08 11:15 PM
39
cve
cve

CVE-2022-4037

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth pro...

8.5CVSS

8.1AI Score

0.004EPSS

2023-01-12 04:15 AM
82
cve
cve

CVE-2022-4054

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to leak a webhook secret token by changing the webhook URL to an endp...

5.5CVSS

5AI Score

0.001EPSS

2023-01-26 09:18 PM
268
cve
cve

CVE-2022-4092

An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input.

8CVSS

7.4AI Score

0.002EPSS

2023-01-26 09:18 PM
23
cve
cve

CVE-2022-4131

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in how the app...

5.3CVSS

4.8AI Score

0.001EPSS

2023-01-12 04:15 AM
86
cve
cve

CVE-2022-4138

A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a maliciou...

8.1CVSS

7.6AI Score

0.001EPSS

2023-02-13 11:15 PM
41
cve
cve

CVE-2022-4143

An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization

6.4CVSS

4.9AI Score

0.001EPSS

2023-06-28 09:15 PM
7
cve
cve

CVE-2022-4167

Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.

7.5CVSS

7.2AI Score

0.002EPSS

2023-01-12 04:15 AM
69
cve
cve

CVE-2022-4201

A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to local addresses when configuring a malicious GitLab Runner.

5.3CVSS

4.7AI Score

0.001EPSS

2023-01-27 10:15 PM
165
cve
cve

CVE-2022-4205

In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash.

7.5CVSS

7.3AI Score

0.001EPSS

2023-01-27 10:15 PM
52
cve
cve

CVE-2022-4255

An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes user email id through webhook payload.

5.3CVSS

4.9AI Score

0.001EPSS

2023-01-27 10:15 PM
163
cve
cve

CVE-2022-4289

An issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version 15.9 before 15.9.2. Google IAP details in Prometheus integration were not hidden, could be leaked from instance, group, or project settings to other users.

6.4CVSS

4.5AI Score

0.001EPSS

2023-03-09 09:15 PM
66
cve
cve

CVE-2022-4331

An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previou...

7.3CVSS

6.9AI Score

0.002EPSS

2023-03-09 10:15 PM
41
cve
cve

CVE-2022-4335

A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host.

4.3CVSS

4.1AI Score

0.001EPSS

2023-01-27 06:15 PM
141
cve
cve

CVE-2022-43411

Jenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

5.3CVSS

5AI Score

0.001EPSS

2022-10-19 04:15 PM
45
4
cve
cve

CVE-2022-4342

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook.

5.5CVSS

4AI Score

0.001EPSS

2023-01-12 04:15 AM
63
cve
cve

CVE-2022-4343

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile.

5CVSS

4.1AI Score

0.0004EPSS

2023-09-01 11:15 AM
182
cve
cve

CVE-2022-4365

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by changing the configured URL in the Sentry error tra...

5.5CVSS

4.1AI Score

0.001EPSS

2023-01-12 04:15 AM
75
cve
cve

CVE-2022-4376

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions, an attacker may be able to map a private email of a GitLab user to their GitLab account on an inst...

4.3CVSS

4.1AI Score

0.001EPSS

2023-05-03 10:15 PM
27
cve
cve

CVE-2022-4462

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response.

5CVSS

4.4AI Score

0.001EPSS

2023-03-09 08:15 PM
38
cve
cve

CVE-2023-0042

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.

6.1CVSS

5.9AI Score

0.001EPSS

2023-01-12 04:15 AM
100
cve
cve

CVE-2023-0050

An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which allows attackers to per...

8.7CVSS

5.2AI Score

0.001EPSS

2023-03-09 10:15 PM
94
cve
cve

CVE-2023-0120

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to edit labels description by an unauthorised user.

4.3CVSS

4.1AI Score

0.0004EPSS

2023-09-01 11:15 AM
108
cve
cve

CVE-2023-0121

A denial of service issue was discovered in GitLab CE/EE affecting all versions starting from 13.2.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2 which allows an attacker to cause high resource consumption using malicious test report...

7.5CVSS

6.9AI Score

0.001EPSS

2023-06-07 05:15 PM
37
cve
cve

CVE-2023-0155

An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown

5.4CVSS

5.5AI Score

0.001EPSS

2023-05-03 09:15 PM
45
cve
cve

CVE-2023-0223

An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Non-project members could retrieve release descriptions via the API, even if the release visibility is restri...

5.3CVSS

5.1AI Score

0.001EPSS

2023-03-09 09:15 PM
37
cve
cve

CVE-2023-0319

An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only.

5.8CVSS

5.1AI Score

0.001EPSS

2023-04-05 08:15 PM
51
cve
cve

CVE-2023-0450

An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. It was possible to add a branch with an ambiguous name that could be used to social engineer users.

4.6CVSS

4.5AI Score

0.001EPSS

2023-04-05 09:15 PM
34
cve
cve

CVE-2023-0483

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by modifying the site.

5.5CVSS

4AI Score

0.001EPSS

2023-03-09 08:15 PM
40
cve
cve

CVE-2023-0485

An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates by doing a diff with ...

6.5CVSS

6.1AI Score

0.003EPSS

2023-05-03 09:15 PM
40
cve
cve

CVE-2023-0508

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. Open redirection was possible via HTTP response splitting in the NPM package API.

4.3CVSS

4.3AI Score

0.001EPSS

2023-06-07 05:15 PM
73
cve
cve

CVE-2023-0518

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. It was possible to trigger a DoS attack by uploading a malicious Helm chart.

7.5CVSS

7.1AI Score

0.001EPSS

2023-02-13 11:15 PM
39
cve
cve

CVE-2023-0523

An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances.

6.1CVSS

5.8AI Score

0.001EPSS

2023-04-05 08:15 PM
36
cve
cve

CVE-2023-0632

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

7.5CVSS

7.1AI Score

0.001EPSS

2023-08-02 12:15 AM
218
cve
cve

CVE-2023-0756

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories with malicious code,...

8CVSS

7.8AI Score

0.018EPSS

2023-05-03 10:15 PM
38
cve
cve

CVE-2023-0805

An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to have access to the public projects of a public group even aft...

8.1CVSS

7.6AI Score

0.003EPSS

2023-05-03 10:15 PM
34
cve
cve

CVE-2023-0838

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

5.5CVSS

3.9AI Score

0.001EPSS

2023-04-05 09:15 PM
44
cve
cve

CVE-2023-0921

A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

4.3CVSS

4AI Score

0.001EPSS

2023-06-06 05:15 PM
74
cve
cve

CVE-2023-0989

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

5.7CVSS

4.9AI Score

0.001EPSS

2023-09-29 07:15 AM
189
cve
cve

CVE-2023-1071

An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic.

4.3CVSS

4.5AI Score

0.001EPSS

2023-04-05 09:15 PM
39
2
cve
cve

CVE-2023-1072

An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible to trigger a resource depletion attack due to improper filtering for number of requests to rea...

5.3CVSS

5.1AI Score

0.001EPSS

2023-03-09 10:15 PM
39
cve
cve

CVE-2023-1084

An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted request.

2.7CVSS

3.7AI Score

0.001EPSS

2023-03-09 08:15 PM
45
cve
cve

CVE-2023-1098

An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configurati...

5.8CVSS

4.8AI Score

0.002EPSS

2023-04-05 08:15 PM
35
cve
cve

CVE-2023-1167

Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.

5.3CVSS

5.4AI Score

0.001EPSS

2023-04-05 09:15 PM
37
cve
cve

CVE-2023-1178

An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a r...

5.7CVSS

5.2AI Score

0.001EPSS

2023-05-03 10:15 PM
30
cve
cve

CVE-2023-1204

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A user could use an unverified email as a public email and commit email by sending a specifically cr...

4.3CVSS

4.2AI Score

0.001EPSS

2023-05-03 09:15 PM
27
Total number of security vulnerabilities984