← Back

Gitlab

gitlab

Vendor: Gitlab • 1,408 CVEs

CVEs (1,408)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
1Gitlab
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip.
1Gitlab
1Gitlab
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title.
1Gitlab
1Gitlab
Jun 17, 2026
Aug 13, 2020
N/A· v4
3.5 LOW· v3
4.9 MEDIUM· v2
For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.
1Gitlab
1Gitlab
Jun 17, 2026
Aug 13, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.
1Gitlab
1Gitlab
Jun 17, 2026
Aug 12, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.
1Gitlab
1Gitlab
Jun 17, 2026
Aug 12, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page
1Gitlab
1Gitlab
Jun 17, 2026
Aug 12, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page
1Gitlab
1Gitlab
Jun 17, 2026
Aug 10, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.
1Gitlab
1Gitlab
Jun 17, 2026
Aug 10, 2020
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.
1Gitlab
1Gitlab
Jun 17, 2026
Aug 10, 2020
N/A· v4
9.6 CRITICAL· v3
5.5 MEDIUM· v2
In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.
1Gitlab
1Gitlab
Jun 17, 2026
Jul 7, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.
1Gitlab
1Gitlab
Jun 17, 2026
Jun 19, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token
1Gitlab
1Gitlab
Jun 17, 2026
Jun 19, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.
1Gitlab
1Gitlab
Jun 17, 2026
Jun 19, 2020
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code
1Gitlab
1Gitlab
Jun 17, 2026
Jun 19, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1
1Gitlab
1Gitlab
Jun 17, 2026
Jun 19, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1
1Gitlab
1Gitlab
Jun 17, 2026
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1
1Gitlab
1Gitlab
Jun 17, 2026
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1
1Gitlab
1Gitlab
Jun 17, 2026
Jun 19, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow
1Gitlab
1Gitlab
Jun 17, 2026
Jun 19, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification