Vulnerability index

Browse CVEs

1,035 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

GitLab MEDIUM 6.1
CVE-2021-22223

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests …

Fix: 13.11.6 / 13.12.6+
Fix from $1,600 2021-07-06
GitLab HIGH 7.5
CVE-2021-22229

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of a…

Fix: 13.11.6 / 13.12.6+
Fix from $1,950 2021-07-06
GitLab MEDIUM 5.4
CVE-2021-22232

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

Fix: 13.11.6 / 13.12.6+
Fix from $1,600 2021-07-06
GitLab MEDIUM 6.5
CVE-2021-22226

Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9

Fix: 13.11.6 / 13.12.6+
Fix from $1,600 2021-07-06
GitLab CRITICAL 9.8
CVE-2021-22175 KEVEPSS 53%

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting…

Fix: 13.6.7 / 13.7.7+
Fix from $2,300 2021-06-11
GitLab MEDIUM 6.5
CVE-2021-22181

A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship an…

Fix: 13.10.5 / 13.11.5+
Fix from $1,600 2021-06-11
GitLab MEDIUM 6.5
CVE-2021-22216

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resourc…

Fix: 13.10.5 / 13.11.5+
Fix from $1,600 2021-06-08
GitLab MEDIUM 5.4
CVE-2021-22220

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

Fix: after 13.12.2
Fix from $1,600 2021-06-08
GitLab MEDIUM 6.5
CVE-2021-22217

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resourc…

Fix: 13.10.5 / 13.11.5+
Fix from $1,600 2021-06-08
GitLab MEDIUM 6.5
CVE-2021-22221

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5,…

Fix: 13.10.5 / 13.11.5+
Fix from $1,600 2021-06-08
GitLab MEDIUM 6.5
CVE-2021-22213

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by get…

Fix: 13.10.5 / 13.11.5+
Fix from $1,600 2021-06-08
GitLab HIGH 8.6
CVE-2021-22214EPSS 28%

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions st…

Fix: 13.10.5 / 13.11.5+
Fix from $1,950 2021-06-08
GitLab HIGH 7.5
CVE-2021-22209

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which…

Fix: 13.9.7 / 13.10.4+
Fix from $1,950 2021-05-06
GitLab MEDIUM 5.3
CVE-2021-22210

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was…

Fix: 13.9.7 / 13.10.4+
Fix from $1,600 2021-05-06
GitLab CRITICAL 10.0
CVE-2021-22205 KEVEPSS 100%

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were pass…

Fix: 13.8.8 / 13.9.6+
Fix from $2,300 2021-04-23
GitLab MEDIUM 5.4
CVE-2021-22199

An issue has been discovered in GitLab affecting all versions starting with 12.9. GitLab was vulnerable to a stored XSS if scoped labels were used.

Fix: 13.8.7 / 13.9.5+
Fix from $1,600 2021-04-22
GitLab MEDIUM 6.5
CVE-2021-22190

A path traversal vulnerability via the GitLab Workhorse in all versions of GitLab could result in the leakage of a JWT token

Fix: 13.7.8 / 13.8.5+
Fix from $1,600 2021-04-12
GitLab CRITICAL 9.8
CVE-2021-22203

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7.9 before 13.8.7, all versions starting from 13.9 before 13.9.5…

Fix: 13.8.7 / 13.9.5+
Fix from $2,300 2021-04-02
GitLab HIGH 7.5
CVE-2021-22200

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of a…

Fix: 13.8.7 / 13.9.5+
Fix from $1,950 2021-04-02
GitLab MEDIUM 6.5
CVE-2021-22201

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the serve…

Fix: 13.9.5 / 13.10.1+
Fix from $1,600 2021-04-02
GitLab MEDIUM 5.4
CVE-2021-22196

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in m…

Fix: 13.8.7 / 13.9.5+
Fix from $1,600 2021-04-02
Gitlab Vscode Extension HIGH 7.8
CVE-2021-22195

Client side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user system

Fix: after 3.15.0
Fix from $1,950 2021-04-01
GitLab MEDIUM 5.5
CVE-2021-22184

An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that …

Fix: 13.6.6 / 13.7.6+
Fix from $1,600 2021-03-26
GitLab HIGH 8.8
CVE-2021-22192EPSS 13%

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary…

Fix: 13.7.9 / 13.8.6+
Fix from $1,950 2021-03-24
GitLab MEDIUM 5.4
CVE-2021-22185

Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site scripting vulnerability via …

Fix: 13.8.5 / 13.9.2+
Fix from $1,600 2021-03-24
GitLab MEDIUM 5.4
CVE-2021-22179

A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature.

Fix: 13.6.6 / 13.7.6+
Fix from $1,600 2021-03-24
GitLab MEDIUM 5.0
CVE-2021-22178

An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integra…

Fix: 13.6.7 / 13.7.7+
Fix from $1,600 2021-03-24
GitLab HIGH 7.2
CVE-2021-22189

Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet…

Fix: 13.6.7 / 13.7.7+
Fix from $1,950 2021-03-04
GitLab MEDIUM 5.4
CVE-2021-22183

An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS in the epics page, which coul…

Fix: 13.6.6 / 13.7.6+
Fix from $1,600 2021-03-04
GitLab MEDIUM 5.4
CVE-2021-22182

An issue has been discovered in GitLab affecting all versions starting with 13.7. GitLab was vulnerable to a stored XSS in merge request.

Fix: 13.7.6 / 13.8.2+
Fix from $1,600 2021-03-03