Vulnerability index

Browse CVEs

1,035 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

GitLab MEDIUM 6.5
CVE-2022-0152

An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all…

Fix: 14.4.5 / 14.5.3+
Fix from $1,600 2022-01-18
GitLab MEDIUM 6.5
CVE-2022-0172

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP res…

Fix: 14.4.5 / 14.5.3+
Fix from $1,600 2022-01-18
GitLab MEDIUM 6.5
CVE-2022-0090

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configure…

Fix: 14.4.5 / 14.5.3+
Fix from $1,600 2022-01-18
GitLab MEDIUM 6.5
CVE-2021-39942

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.…

Fix: 14.3.6 / 14.4.4+
Fix from $1,600 2022-01-18
GitLab MEDIUM 5.4
CVE-2021-39946

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS …

Fix: 14.3.6 / 14.4.4+
Fix from $1,600 2022-01-18
GitLab HIGH 8.8
CVE-2021-39937

A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions st…

Fix: 14.3.6 / 14.4.4+
Fix from $1,950 2021-12-13
GitLab HIGH 7.5
CVE-2021-39935 KEVEPSS 36%

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, …

Fix: 14.3.6 / 14.4.4+
Fix from $1,950 2021-12-13
GitLab HIGH 7.1
CVE-2021-39944

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, …

Fix: 14.3.6 / 14.4.4+
Fix from $1,950 2021-12-13
GitLab MEDIUM 6.5
CVE-2021-39933

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4,…

Fix: 14.3.6 / 14.4.4+
Fix from $1,600 2021-12-13
GitLab MEDIUM 6.5
CVE-2021-39938

A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions…

Fix: 14.3.6 / 14.4.4+
Fix from $1,600 2021-12-13
GitLab MEDIUM 6.5
CVE-2021-39939

An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting fr…

Fix: 14.3.6 / 14.4.4+
Fix from $1,600 2021-12-13
GitLab MEDIUM 6.5
CVE-2021-39940

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, …

Fix: 14.3.6 / 14.4.4+
Fix from $1,600 2021-12-13
GitLab MEDIUM 5.3
CVE-2021-39941

An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to se…

Fix: 14.3.6 / 14.4.4+
Fix from $1,600 2021-12-13
GitLab MEDIUM 6.5
CVE-2021-39917

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, …

Fix: 14.3.6 / 14.4.4+
Fix from $1,600 2021-12-13
GitLab MEDIUM 5.3
CVE-2021-39915

Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 b…

Fix: 14.3.6 / 14.4.4+
Fix from $1,600 2021-12-13
GitLab CRITICAL 9.8
CVE-2021-39890

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

Fix: 14.1.7 / 14.2.5+
Fix from $2,300 2021-12-06
GitLab HIGH 7.5
CVE-2021-22170

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content

Fix: 13.5.6 / 13.6.4+
Fix from $1,950 2021-12-06
GitLab MEDIUM 6.7
CVE-2021-39913

Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before…

Fix: 14.2.6 / 14.3.4+
Fix from $1,600 2021-11-05
GitLab MEDIUM 5.3
CVE-2021-39907

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in h…

Fix: 14.2.6 / 14.3.4+
Fix from $1,600 2021-11-05
GitLab MEDIUM 5.3
CVE-2021-39909

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions st…

Fix: 14.2.6 / 14.3.4+
Fix from $1,600 2021-11-05
GitLab MEDIUM 5.3
CVE-2021-39912

A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory…

Fix: 14.2.6 / 14.3.4+
Fix from $1,600 2021-11-05
GitLab MEDIUM 6.1
CVE-2021-39906EPSS 61%

Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's beh…

Fix: 14.2.6 / 14.3.4+
Fix from $1,600 2021-11-05
GitLab MEDIUM 5.3
CVE-2021-39897

Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to sti…

Fix: 12.9.8 / 12.10.7+
Fix from $1,600 2021-11-05
GitLab MEDIUM 5.3
CVE-2021-39898

In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project whi…

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-11-05
GitLab MEDIUM 5.4
CVE-2021-22260

A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions…

Fix: 14.0.9 / 14.1.4+
Fix from $1,600 2021-11-05
GitLab MEDIUM 6.5
CVE-2021-39903

In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project t…

Fix: 14.2.6 / 14.3.4+
Fix from $1,600 2021-11-04
GitLab MEDIUM 6.5
CVE-2021-22263

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all ve…

Fix: 14.0.9 / 14.1.4+
Fix from $1,600 2021-10-11
GitLab MEDIUM 6.5
CVE-2021-39880

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions st…

Fix: 14.0.9 / 14.1.4+
Fix from $1,600 2021-10-05
GitLab MEDIUM 6.5
CVE-2021-22264

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all ve…

Fix: 14.0.9 / 14.1.4+
Fix from $1,600 2021-10-05
GitLab MEDIUM 5.3
CVE-2021-22257

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all ve…

Fix: 14.0.9 / 14.1.4+
Fix from $1,600 2021-10-05