Vulnerability index

Browse CVEs

1,035 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

GitLab MEDIUM 6.1
CVE-2018-16050

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merg…

Fix: 11.1.5 / 11.2.2+
Fix from $1,600 2018-10-03
GitLab MEDIUM 5.4
CVE-2018-12605

An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' contained a XSS issue due to …

Fix: 10.7.6+
Fix from $1,600 2018-08-03
GitLab MEDIUM 5.4
CVE-2018-12606

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki cont…

Fix: 10.7.6 / 10.8.5+
Fix from $1,600 2018-08-03
GitLab MEDIUM 5.4
CVE-2018-12607

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts fe…

Fix: 10.7.6 / 10.8.5+
Fix from $1,600 2018-08-03
GitLab HIGH 8.8
CVE-2018-14603

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. CSRF can occur in t…

Fix: 10.8.7 / 11.0.5+
Fix from $1,950 2018-07-27
GitLab HIGH 7.5
CVE-2018-14601

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.2. A Denial of Service can occur because Markdown rendering tim…

Fix: 11.1.2+
Fix from $1,950 2018-07-27
GitLab HIGH 7.5
CVE-2018-14602

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. Information Disclos…

Fix: 10.8.7 / 11.0.5+
Fix from $1,950 2018-07-27
GitLab MEDIUM 6.1
CVE-2018-14604

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in th…

Fix: 10.8.7 / 11.0.5+
Fix from $1,600 2018-07-27
GitLab MEDIUM 5.4
CVE-2018-14605

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in th…

Fix: 10.8.7 / 11.0.5+
Fix from $1,600 2018-07-27
GitLab MEDIUM 5.4
CVE-2018-14606

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur via a…

Fix: 10.8.7 / 11.0.5+
Fix from $1,600 2018-07-27
GitLab CRITICAL 9.8
CVE-2018-14364EPSS 50%

GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and …

Fix: 10.7.7 / 10.8.6+
Fix from $2,300 2018-07-18
GitLab HIGH 8.1
CVE-2017-0921

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsCont…

Fix: 10.1.6 / 10.2.6+
Fix from $1,950 2018-07-03
GitLab HIGH 7.5
CVE-2017-0919

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import compo…

Fix: 10.1.6 / 10.2.6+
Fix from $1,950 2018-07-03
GitLab MEDIUM 6.1
CVE-2018-10379

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. T…

Fix: 10.5.8 / 10.6.5+
Fix from $1,600 2018-05-31
GitLab MEDIUM 6.5
CVE-2018-8801

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

Fix: 10.3+
Fix from $1,600 2018-04-25
GitLab MEDIUM 6.1
CVE-2018-9243

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request compone…

Fix: 10.4.7 / 10.5.7+
Fix from $1,600 2018-04-05
GitLab MEDIUM 6.1
CVE-2018-9244

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component …

Fix: 10.4.7 / 10.5.7+
Fix from $1,600 2018-04-05
GitLab CRITICAL 9.8
CVE-2018-8971

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading …

Fix: after 10.5.5
Fix from $2,300 2018-03-24
GitLab HIGH 7.8
CVE-2018-3710

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote …

Fix: after 10.3.3
Fix from $1,950 2018-03-21
GitLab CRITICAL 9.8
CVE-2017-0915EPSS 6%

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execu…

Fix: after 10.3.3
Fix from $2,300 2018-03-21
GitLab CRITICAL 9.8
CVE-2017-0916EPSS 6%

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting …

Fix: after 10.3.3
Fix from $2,300 2018-03-21
GitLab HIGH 8.8
CVE-2017-0918

Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution.

Fix: after 10.3.3
Fix from $1,950 2018-03-21
GitLab HIGH 8.8
CVE-2017-0926

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user …

Fix: after 10.3.3
Fix from $1,950 2018-03-21
GitLab HIGH 7.5
CVE-2017-0914

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting …

Fix: after 10.3.3
Fix from $1,950 2018-03-21
GitLab HIGH 7.5
CVE-2017-0922

Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in…

Fix: after 10.3.3
Fix from $1,950 2018-03-21
GitLab HIGH 7.2
CVE-2017-0925

Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoin…

Fix: after 10.3.3
Fix from $1,950 2018-03-21
GitLab MEDIUM 6.5
CVE-2017-0927

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use…

Fix: after 10.3.3
Fix from $1,600 2018-03-21
GitLab MEDIUM 6.1
CVE-2017-0917

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scriptin…

Fix: after 10.3.3
Fix from $1,600 2018-03-21
GitLab MEDIUM 6.1
CVE-2017-0923

Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site …

Mitigation only
Fix from $1,600 2018-03-21
GitLab MEDIUM 6.1
CVE-2017-0924

Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in persistent cross site scriptin…

Fix: after 10.3.3
Fix from $1,600 2018-03-21