← Back

Gitlab

gitlab

1,397 CVEs • 11 products

Products (11)

Click to collapse
Toggle
Gitlab
gitlab
Gitlab Shell
gitlab-shell
Runner
runner
Omnibus
omnibus
Gitaly
gitaly
Gitlab Runner
gitlab_runner
\

CVEs (1,397)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
1Gitlab
Nov 21, 2024
Sep 14, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.
1Gitlab
1Gitlab
Nov 21, 2024
Sep 14, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.
1Gitlab
1Gitlab
Nov 21, 2024
Sep 14, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues
1Gitlab
1Gitlab
Nov 21, 2024
Sep 14, 2020
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token
1Gitlab
1Gitlab
Nov 21, 2024
Aug 13, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.
1Gitlab
1Gitlab
Nov 21, 2024
Aug 13, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature
1Gitlab
1Gitlab
Nov 21, 2024
Aug 13, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip.
1Gitlab
1Gitlab
Nov 21, 2024
Aug 13, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title.
1Gitlab
1Gitlab
Nov 21, 2024
Aug 13, 2020
N/A· v4
3.5 LOW· v3
4.9 MEDIUM· v2
For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.
1Gitlab
1Gitlab
Nov 21, 2024
Aug 13, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.
1Gitlab
1Gitlab
Nov 21, 2024
Aug 12, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.
1Gitlab
1Gitlab
Nov 21, 2024
Aug 12, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page
1Gitlab
1Gitlab
Nov 21, 2024
Aug 12, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page
1Gitlab
1Runner
Nov 21, 2024
Aug 10, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.
1Gitlab
1Gitlab
Nov 21, 2024
Aug 10, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.
1Gitlab
1Gitlab
Nov 21, 2024
Aug 10, 2020
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.
1Gitlab
1Gitlab
Nov 21, 2024
Aug 10, 2020
N/A· v4
9.6 CRITICAL· v3
5.5 MEDIUM· v2
In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.
1Gitlab
1Gitlab
Nov 21, 2024
Jul 7, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.
1Gitlab
1Gitlab Vscode Extension
Nov 21, 2024
Jun 22, 2020
N/A· v4
8.6 HIGH· v3
6.8 MEDIUM· v2
Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system
1Gitlab
1Gitlab
Nov 21, 2024
Jun 19, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token