Vulnerability index

Browse CVEs

1,035 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

GitLab HIGH 7.5
CVE-2021-39893

A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

Fix: 14.1.7 / 14.2.5+
Fix from $1,950 2021-10-05
GitLab MEDIUM 6.5
CVE-2021-39869

In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-10-05
GitLab MEDIUM 6.5
CVE-2021-39872

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLa…

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-10-05
GitLab MEDIUM 5.4
CVE-2021-39878

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbi…

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-10-05
GitLab MEDIUM 5.4
CVE-2021-39894

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit…

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-10-05
GitLab MEDIUM 5.3
CVE-2021-39875

In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an AP…

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-10-05
GitLab MEDIUM 5.3
CVE-2021-39882

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-10-05
GitLab HIGH 8.1
CVE-2021-39867

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server…

Fix: 14.1.7 / 14.2.5+
Fix from $1,950 2021-10-05
GitLab MEDIUM 5.4
CVE-2021-39866

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-10-05
GitLab MEDIUM 5.4
CVE-2021-39887

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbi…

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-10-05
GitLab MEDIUM 5.5
CVE-2021-39877

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a special…

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-10-04
GitLab MEDIUM 5.4
CVE-2021-39885

A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.…

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-10-04
GitLab MEDIUM 6.5
CVE-2021-22259

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

Fix: 14.1.7+
Fix from $1,600 2021-10-04
GitLab MEDIUM 6.5
CVE-2021-22244

Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability …

Fix: 13.12.9 / 14.0.7+
Fix from $1,600 2021-08-25
GitLab MEDIUM 5.4
CVE-2021-22250

Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators cr…

Fix: 13.12.9 / 14.0.7+
Fix from $1,600 2021-08-25
GitLab MEDIUM 5.4
CVE-2021-22256

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

Fix: 13.12.9 / 14.0.7+
Fix from $1,600 2021-08-25
GitLab HIGH 8.8
CVE-2021-22236

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability i…

Fix: 14.1.2+
Fix from $1,950 2021-08-25
GitLab MEDIUM 5.4
CVE-2021-22242EPSS 64%

Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting v…

Fix: 13.12.9 / 14.0.7+
Fix from $1,600 2021-08-25
GitLab MEDIUM 6.5
CVE-2021-22252

A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which…

Fix: 13.12.9 / 14.0.7+
Fix from $1,600 2021-08-23
GitLab MEDIUM 5.4
CVE-2021-22253

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments t…

Fix: 13.12.9 / 14.0.7+
Fix from $1,600 2021-08-23
GitLab MEDIUM 5.3
CVE-2021-22248

Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline info…

Fix: 13.12.9 / 14.0.7+
Fix from $1,600 2021-08-23
GitLab MEDIUM 6.5
CVE-2021-22246

A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of servic…

Fix: 13.11.6 / 13.12.6+
Fix from $1,600 2021-08-20
GitLab MEDIUM 5.4
CVE-2021-22238EPSS 72%

An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature i…

Fix: 13.12.9 / 14.0.7+
Fix from $1,600 2021-08-20
GitLab MEDIUM 6.4
CVE-2021-22234

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12…

Fix: after 14.0.4
Fix from $1,600 2021-08-05
GitLab MEDIUM 5.4
CVE-2021-22241

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via …

Fix: 14.0.7 / 14.1.2+
Fix from $1,600 2021-08-05
GitLab MEDIUM 6.5
CVE-2021-22224

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacke…

Fix: 13.12.6 / 14.0.2+
Fix from $1,600 2021-07-07
GitLab MEDIUM 5.4
CVE-2021-22225

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability …

Fix: 13.11.6 / 13.12.6+
Fix from $1,600 2021-07-07
GitLab HIGH 7.2
CVE-2021-22230

Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and l…

Fix: 13.11.6 / 13.12.6+
Fix from $1,950 2021-07-07
GitLab MEDIUM 6.1
CVE-2021-22227

A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a v…

Fix: 13.11.6 / 13.12.6+
Fix from $1,600 2021-07-07
GitLab MEDIUM 6.5
CVE-2021-22228

An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions start…

Fix: 13.11.6 / 13.12.6+
Fix from $1,600 2021-07-06