Lucene search

K

Gitlab Security Vulnerabilities

cve
cve

CVE-2023-1210

An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for groups that restrict membership by email doma...

4.3CVSS

4AI Score

0.0005EPSS

2023-08-02 12:15 AM
210
cve
cve

CVE-2023-1265

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from a...

5.4CVSS

4.2AI Score

0.003EPSS

2023-05-03 09:15 PM
22
cve
cve

CVE-2023-1279

An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 where it was possible to create a URL that would redirect to a different project.

6.1CVSS

5.8AI Score

0.0005EPSS

2023-09-01 11:15 AM
102
cve
cve

CVE-2023-1401

An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.

5CVSS

4.3AI Score

0.001EPSS

2023-07-26 07:15 AM
13
cve
cve

CVE-2023-1417

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group.

4.3CVSS

4.5AI Score

0.001EPSS

2023-04-05 09:15 PM
37
cve
cve

CVE-2023-1555

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API.

4.3CVSS

4.2AI Score

0.0004EPSS

2023-09-01 11:15 AM
2500
cve
cve

CVE-2023-1621

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to commit to projects even from a restricted IP address.

6.5CVSS

6AI Score

0.001EPSS

2023-06-06 08:15 PM
46
cve
cve

CVE-2023-1708

An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine.

9.8CVSS

9.2AI Score

0.002EPSS

2023-04-05 09:15 PM
78
cve
cve

CVE-2023-1710

A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to 15.10.1 allows an attacker to view the count of internal notes for a given issue.

5.3CVSS

4.9AI Score

0.001EPSS

2023-04-05 09:15 PM
33
cve
cve

CVE-2023-1733

A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1.

7.5CVSS

7.1AI Score

0.001EPSS

2023-04-05 08:15 PM
42
cve
cve

CVE-2023-1787

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A search timeout could be triggered if a specific HTML payload was used in the issue description.

5.3CVSS

5.1AI Score

0.001EPSS

2023-04-05 09:15 PM
53
cve
cve

CVE-2023-1825

An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. It was possible to disclose issue notes to an unauthorized user at project export.

4.3CVSS

4.1AI Score

0.001EPSS

2023-06-07 05:15 PM
46
cve
cve

CVE-2023-1836

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository in "raw" mode, it can be made to render as HT...

5.4CVSS

4.8AI Score

0.002EPSS

2023-05-03 09:15 PM
28
cve
cve

CVE-2023-1936

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a service desk issue.

4.3CVSS

4AI Score

0.001EPSS

2023-07-11 08:15 AM
69
cve
cve

CVE-2023-1965

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens...

6.8CVSS

5.9AI Score

0.003EPSS

2023-05-03 09:15 PM
32
cve
cve

CVE-2023-2001

An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could potentially lead a victim to download malicious code.

4.3CVSS

4AI Score

0.001EPSS

2023-06-07 05:15 PM
72
cve
cve

CVE-2023-2013

An issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and...

4.3CVSS

4.2AI Score

0.001EPSS

2023-06-07 05:15 PM
36
cve
cve

CVE-2023-2015

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A reflected XSS was possible when creating new abuse reports which allows attackers to perform arbit...

6.1CVSS

5.7AI Score

0.002EPSS

2023-06-07 05:15 PM
33
cve
cve

CVE-2023-2022

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have a...

4.3CVSS

4.1AI Score

0.0005EPSS

2023-08-02 09:15 AM
312
cve
cve

CVE-2023-2030

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

5.3CVSS

5.2AI Score

0.0005EPSS

2024-01-12 02:15 PM
19
cve
cve

CVE-2023-2069

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables.

6.4CVSS

4.1AI Score

0.001EPSS

2023-05-03 09:15 PM
69
cve
cve

CVE-2023-2132

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A DollarMathPostFilter Regular Expression Denial of Service in was possible by sending crafted paylo...

7.5CVSS

7.1AI Score

0.001EPSS

2023-06-06 05:15 PM
28
cve
cve

CVE-2023-2164

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL...

5.4CVSS

4.8AI Score

0.0005EPSS

2023-08-02 12:15 AM
31
cve
cve

CVE-2023-2181

An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI.

6.5CVSS

6AI Score

0.001EPSS

2023-05-12 09:15 PM
24
cve
cve

CVE-2023-2182

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions when OpenID Connect is enabled on an instance, it may allow users who are marked as 'external' to become 'regular' users thu...

8.8CVSS

8.6AI Score

0.002EPSS

2023-05-03 10:15 PM
29
cve
cve

CVE-2023-2190

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. It may be possible for users to view new commits to private projects in a fork created while the pro...

6.5CVSS

6AI Score

0.001EPSS

2023-07-13 02:15 AM
51
cve
cve

CVE-2023-2198

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markd...

7.5CVSS

7.1AI Score

0.001EPSS

2023-06-07 05:15 PM
66
cve
cve

CVE-2023-2199

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_mark...

7.5CVSS

7.1AI Score

0.001EPSS

2023-06-07 05:15 PM
39
cve
cve

CVE-2023-2200

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML in an email address field.

5.4CVSS

5AI Score

0.001EPSS

2023-07-13 03:15 AM
87
cve
cve

CVE-2023-2232

An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira prefix

6.5CVSS

6AI Score

0.001EPSS

2023-06-28 09:15 PM
6
cve
cve

CVE-2023-2233

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.

4.3CVSS

4.1AI Score

0.0004EPSS

2023-09-29 07:15 AM
184
cve
cve

CVE-2023-2442

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of vic...

8.7CVSS

4.9AI Score

0.003EPSS

2023-06-07 04:15 PM
117
cve
cve

CVE-2023-2478

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a GraphQL endpoint to attach...

9.6CVSS

6AI Score

0.001EPSS

2023-05-08 09:15 PM
375
cve
cve

CVE-2023-2485

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they impor...

4.9CVSS

4.7AI Score

0.001EPSS

2023-06-07 05:15 PM
35
cve
cve

CVE-2023-2576

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CODEOWNERS rules and merge to a protected branch.

4.3CVSS

4AI Score

0.0005EPSS

2023-07-13 03:15 AM
108
cve
cve

CVE-2023-2589

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker can clone a repository from a public project, from a disallowed IP, even after the top-leve...

5.9CVSS

4.9AI Score

0.001EPSS

2023-06-07 05:15 PM
39
cve
cve

CVE-2023-2620

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. Thi...

5.5CVSS

3.6AI Score

0.001EPSS

2023-07-13 03:15 AM
39
cve
cve

CVE-2023-2825

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

10CVSS

7.2AI Score

0.159EPSS

2023-05-26 09:15 PM
291
cve
cve

CVE-2023-3102

A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR.

5.3CVSS

4.7AI Score

0.001EPSS

2023-07-21 04:15 PM
78
cve
cve

CVE-2023-3115

An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories...

5.4CVSS

4.2AI Score

0.0004EPSS

2023-09-29 07:15 AM
192
cve
cve

CVE-2023-3205

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

6.5CVSS

6AI Score

0.0004EPSS

2023-09-01 11:15 AM
433
cve
cve

CVE-2023-3210

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

6.5CVSS

6AI Score

0.0004EPSS

2023-09-01 11:15 AM
407
cve
cve

CVE-2023-3246

An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job processor.

4.3CVSS

4.2AI Score

0.0004EPSS

2023-11-06 01:15 PM
295
cve
cve

CVE-2023-3362

An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.

5.3CVSS

4.7AI Score

0.001EPSS

2023-07-13 03:15 AM
123
cve
cve

CVE-2023-3363

An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to default.

3.9CVSS

3.8AI Score

0.0004EPSS

2023-07-13 03:15 AM
58
cve
cve

CVE-2023-3364

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use AutolinkFilt...

7.5CVSS

7.1AI Score

0.001EPSS

2023-08-02 12:15 AM
278
cve
cve

CVE-2023-3385

An issue has been discovered in GitLab affecting all versions starting from 8.10 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Under specific circumstances, a user importing a project 'from export' could access and read unrelated files ...

6.5CVSS

5.9AI Score

0.001EPSS

2023-08-02 12:15 AM
275
cve
cve

CVE-2023-3399

An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD variables using the custom p...

8.5CVSS

7.1AI Score

0.001EPSS

2023-11-06 01:15 PM
292
cve
cve

CVE-2023-3401

An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. The main branch of a repository with a specially designed name allows an attacker to create repositories with malicious code.

6.5CVSS

6AI Score

0.0005EPSS

2023-08-02 09:15 AM
325
cve
cve

CVE-2023-3413

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to onl...

7.5CVSS

7.1AI Score

0.001EPSS

2023-09-29 09:15 AM
91
Total number of security vulnerabilities984