Vulnerability index

Browse CVEs

1,035 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2022-0152 An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all… GitLab 14.4.5 / 14.5.3+ Fix from $1,6002022-01-18 MEDIUM 6.5 CVE-2022-0172 An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP res… GitLab 14.4.5 / 14.5.3+ Fix from $1,6002022-01-18 MEDIUM 6.5 CVE-2022-0090 An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configure… GitLab 14.4.5 / 14.5.3+ Fix from $1,6002022-01-18 MEDIUM 6.5 CVE-2021-39942 A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.… GitLab 14.3.6 / 14.4.4+ Fix from $1,6002022-01-18 MEDIUM 5.4 CVE-2021-39946 Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS … GitLab 14.3.6 / 14.4.4+ Fix from $1,6002022-01-18 HIGH 8.8 CVE-2021-39937 A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions st… GitLab 14.3.6 / 14.4.4+ Fix from $1,9502021-12-13 HIGH 7.5 CVE-2021-39935 KEVEPSS 36% An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, … GitLab 14.3.6 / 14.4.4+ Fix from $1,9502021-12-13 HIGH 7.1 CVE-2021-39944 An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, … GitLab 14.3.6 / 14.4.4+ Fix from $1,9502021-12-13 MEDIUM 6.5 CVE-2021-39933 An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4,… GitLab 14.3.6 / 14.4.4+ Fix from $1,6002021-12-13 MEDIUM 6.5 CVE-2021-39938 A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions… GitLab 14.3.6 / 14.4.4+ Fix from $1,6002021-12-13 MEDIUM 6.5 CVE-2021-39939 An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting fr… GitLab 14.3.6 / 14.4.4+ Fix from $1,6002021-12-13 MEDIUM 6.5 CVE-2021-39940 An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, … GitLab 14.3.6 / 14.4.4+ Fix from $1,6002021-12-13 MEDIUM 5.3 CVE-2021-39941 An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to se… GitLab 14.3.6 / 14.4.4+ Fix from $1,6002021-12-13 MEDIUM 6.5 CVE-2021-39917 An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, … GitLab 14.3.6 / 14.4.4+ Fix from $1,6002021-12-13 MEDIUM 5.3 CVE-2021-39915 Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 b… GitLab 14.3.6 / 14.4.4+ Fix from $1,6002021-12-13 CRITICAL 9.8 CVE-2021-39890 It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above. GitLab 14.1.7 / 14.2.5+ Fix from $2,3002021-12-06 HIGH 7.5 CVE-2021-22170 Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content GitLab 13.5.6 / 13.6.4+ Fix from $1,9502021-12-06 MEDIUM 6.7 CVE-2021-39913 Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before… GitLab 14.2.6 / 14.3.4+ Fix from $1,6002021-11-05 MEDIUM 5.3 CVE-2021-39907 A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in h… GitLab 14.2.6 / 14.3.4+ Fix from $1,6002021-11-05 MEDIUM 5.3 CVE-2021-39909 Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions st… GitLab 14.2.6 / 14.3.4+ Fix from $1,6002021-11-05 MEDIUM 5.3 CVE-2021-39912 A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory… GitLab 14.2.6 / 14.3.4+ Fix from $1,6002021-11-05 MEDIUM 6.1 CVE-2021-39906EPSS 61% Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's beh… GitLab 14.2.6 / 14.3.4+ Fix from $1,6002021-11-05 MEDIUM 5.3 CVE-2021-39897 Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to sti… GitLab 12.9.8 / 12.10.7+ Fix from $1,6002021-11-05 MEDIUM 5.3 CVE-2021-39898 In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project whi… GitLab 14.1.7 / 14.2.5+ Fix from $1,6002021-11-05 MEDIUM 5.4 CVE-2021-22260 A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions… GitLab 14.0.9 / 14.1.4+ Fix from $1,6002021-11-05 MEDIUM 6.5 CVE-2021-39903 In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project t… GitLab 14.2.6 / 14.3.4+ Fix from $1,6002021-11-04 MEDIUM 6.5 CVE-2021-22263 An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all ve… GitLab 14.0.9 / 14.1.4+ Fix from $1,6002021-10-11 MEDIUM 6.5 CVE-2021-39880 A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions st… GitLab 14.0.9 / 14.1.4+ Fix from $1,6002021-10-05 MEDIUM 6.5 CVE-2021-22264 An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all ve… GitLab 14.0.9 / 14.1.4+ Fix from $1,6002021-10-05 MEDIUM 5.3 CVE-2021-22257 An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all ve… GitLab 14.0.9 / 14.1.4+ Fix from $1,6002021-10-05