Vulnerability index

Browse CVEs

1,035 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

GitLab MEDIUM 5.3
CVE-2021-22188

An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorise…

Fix: 13.6.7 / 13.7.7+
Fix from $1,600 2021-03-03
GitLab HIGH 7.5
CVE-2021-22166

An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method

Fix: 13.7.2+
Fix from $1,950 2021-01-15
GitLab HIGH 7.5
CVE-2021-22167

An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have …

Fix: 13.5.6 / 13.6.4+
Fix from $1,950 2021-01-15
GitLab MEDIUM 6.5
CVE-2021-22168

A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.

Fix: 13.5.6 / 13.6.4+
Fix from $1,600 2021-01-15
GitLab MEDIUM 6.5
CVE-2021-22171

Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click …

Fix: 13.5.6 / 13.6.4+
Fix from $1,600 2021-01-15
GitLab MEDIUM 6.5
CVE-2020-26414

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes exe…

Fix: 13.5.6 / 13.6.4+
Fix from $1,600 2021-01-15
GitLab MEDIUM 5.3
CVE-2020-26408

A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows a…

Fix: 13.4.7 / 13.5.5+
Fix from $1,600 2020-12-11
GitLab MEDIUM 5.3
CVE-2020-26413EPSS 35%

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in u…

Fix: 13.6.2+
Fix from $1,600 2020-12-11
GitLab MEDIUM 5.3
CVE-2020-26417

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6…

Fix: 13.4.7 / 13.5.5+
Fix from $1,600 2020-12-11
GitLab MEDIUM 6.5
CVE-2020-26409

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource b…

Fix: 13.4.7 / 13.5.5+
Fix from $1,600 2020-12-11
GitLab MEDIUM 5.4
CVE-2020-26407

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cro…

Fix: 13.4.7 / 13.5.5+
Fix from $1,600 2020-12-10
GitLab HIGH 8.2
CVE-2020-13356

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protectio…

Fix: 13.3.9 / 13.4.5+
Fix from $1,950 2020-11-19
GitLab HIGH 7.6
CVE-2020-13359

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to ove…

Fix: 13.3.9 / 13.4.5+
Fix from $1,950 2020-11-19
GitLab HIGH 8.1
CVE-2020-13355

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker …

Fix: 13.3.9 / 13.4.5+
Fix from $1,950 2020-11-19
GitLab HIGH 7.1
CVE-2020-26405

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary loca…

Fix: 13.3.9 / 13.4.5+
Fix from $1,950 2020-11-17
GitLab MEDIUM 5.7
CVE-2020-13348

An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a br…

Fix: 13.3.9 / 13.4.5+
Fix from $1,600 2020-11-17
GitLab MEDIUM 6.5
CVE-2020-13351

Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pip…

Fix: 13.3.9 / 13.4.5+
Fix from $1,600 2020-11-17
GitLab MEDIUM 5.5
CVE-2020-13358

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected …

Fix: 13.3.9 / 13.4.5+
Fix from $1,600 2020-11-17
GitLab MEDIUM 5.3
CVE-2020-13352

Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions…

Fix: 13.3.9 / 13.4.5+
Fix from $1,600 2020-11-17
GitLab MEDIUM 5.3
CVE-2020-26406

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through …

Fix: 13.3.9 / 13.4.5+
Fix from $1,600 2020-11-17
Runner HIGH 7.5
CVE-2020-13327

An issue has been discovered in GitLab Runner affecting all versions starting from 13.4.0 before 13.4.2, all versions starting from 13.3.0 before 13.…

Fix: 13.2.10 / 13.3.7+
Fix from $1,950 2020-10-22
GitLab HIGH 8.7
CVE-2020-13340EPSS 69%

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log

Fix: 13.2.10 / 13.3.7+
Fix from $1,950 2020-10-08
GitLab MEDIUM 6.5
CVE-2020-13339

An issue has been discovered in GitLab affecting all versions before 13.2.10, 13.3.7 and 13.4.2: XSS in SVG File Preview. Overall impact is limited d…

Fix: 13.2.10 / 13.3.7+
Fix from $1,600 2020-10-08
GitLab CRITICAL 9.1
CVE-2020-13347

A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Win…

Fix: 13.2.4 / 13.3.2+
Fix from $2,300 2020-10-07
GitLab HIGH 7.5
CVE-2020-13334

In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentia…

Fix: 13.2.10 / 13.3.7+
Fix from $1,950 2020-10-07
GitLab MEDIUM 6.5
CVE-2020-13346

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access con…

Fix: 13.2.10 / 13.3.7+
Fix from $1,600 2020-10-07
GitLab HIGH 8.8
CVE-2020-13343

An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template

Fix: after 13.4.3
Fix from $1,950 2020-10-06
GitLab MEDIUM 5.4
CVE-2020-13345

An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes

Fix: 13.2.10 / 13.3.7+
Fix from $1,600 2020-10-06
GitLab MEDIUM 5.4
CVE-2020-13338

An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discover…

Fix: 12.10.13 / 13.0.8+
Fix from $1,600 2020-10-02
GitLab MEDIUM 5.4
CVE-2020-13331

An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges.

Fix: 12.10.13+
Fix from $1,600 2020-09-30