Vulnerability index

Browse CVEs

1,035 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

GitLab MEDIUM 6.5
CVE-2014-8540

The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging impro…

Fix: 7.4.3+
Fix from $1,600 2018-01-05
GitLab MEDIUM 5.9
CVE-2017-17716

GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release …

Patch available
Fix from $1,600 2017-12-17
GitLab HIGH 8.8
CVE-2017-12426

GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before …

Fix: after 8.17.7
Fix from $1,950 2017-08-14
GitLab MEDIUM 6.5
CVE-2017-11437

GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to us…

Mitigation only
Fix from $1,600 2017-08-02
GitLab MEDIUM 6.3
CVE-2017-11438

GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group …

Mitigation only
Fix from $1,600 2017-08-02
GitLab MEDIUM 6.1
CVE-2017-8778

GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG doc…

Fix: after 8.14.9
Fix from $1,600 2017-05-04
GitLab HIGH 8.2
CVE-2016-9469

Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects…

Patch available
Fix from $1,950 2017-03-28
GitLab MEDIUM 6.3
CVE-2017-0882

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15…

Patch available
Fix from $1,600 2017-03-28
GitLab HIGH 8.8
CVE-2016-4340EPSS 10%

The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4…

Patch available
Fix from $1,950 2017-01-23
GitLab MEDIUM 6.5
CVE-2016-9086EPSS 5%

GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature …

Patch available
Fix from $1,600 2016-11-03
GitLab MEDIUM 6.5
CVE-2013-4489

The Grit gem for Ruby, as used in GitLab 5.2 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands, as d…

Patch available
Fix from $1,600 2014-05-17
GitLab MEDIUM 6.5
CVE-2013-4546

The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via th…

Fix: after 1.7.3
Fix from $1,600 2014-05-13
GitLab MEDIUM 6.5
CVE-2013-4490EPSS 42%

The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote …

Fix: after 1.7.2
Fix from $1,600 2014-05-13
GitLab MEDIUM 6.8
CVE-2013-4580

GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impe…

Fix: after 5.4.1
Fix from $1,600 2014-05-12
GitLab MEDIUM 6.8
CVE-2013-4581

GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to exe…

Fix: after 6.2.3
Fix from $1,600 2014-05-12