Vulnerability index

Browse CVEs

1,035 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2021-39893 A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation. GitLab 14.1.7 / 14.2.5+ Fix from $1,9502021-10-05 MEDIUM 6.5 CVE-2021-39869 In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project. GitLab 14.1.7 / 14.2.5+ Fix from $1,6002021-10-05 MEDIUM 6.5 CVE-2021-39872 In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLa… GitLab 14.1.7 / 14.2.5+ Fix from $1,6002021-10-05 MEDIUM 5.4 CVE-2021-39878 A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbi… GitLab 14.1.7 / 14.2.5+ Fix from $1,6002021-10-05 MEDIUM 5.4 CVE-2021-39894 In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit… GitLab 14.1.7 / 14.2.5+ Fix from $1,6002021-10-05 MEDIUM 5.3 CVE-2021-39875 In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an AP… GitLab 14.1.7 / 14.2.5+ Fix from $1,6002021-10-05 MEDIUM 5.3 CVE-2021-39882 In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user. GitLab 14.1.7 / 14.2.5+ Fix from $1,6002021-10-05 HIGH 8.1 CVE-2021-39867 In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server… GitLab 14.1.7 / 14.2.5+ Fix from $1,9502021-10-05 MEDIUM 5.4 CVE-2021-39866 A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens. GitLab 14.1.7 / 14.2.5+ Fix from $1,6002021-10-05 MEDIUM 5.4 CVE-2021-39887 A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbi… GitLab 14.1.7 / 14.2.5+ Fix from $1,6002021-10-05 MEDIUM 5.5 CVE-2021-39877 A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a special… GitLab 14.1.7 / 14.2.5+ Fix from $1,6002021-10-04 MEDIUM 5.4 CVE-2021-39885 A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.… GitLab 14.1.7 / 14.2.5+ Fix from $1,6002021-10-04 MEDIUM 6.5 CVE-2021-22259 A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API. GitLab 14.1.7+ Fix from $1,6002021-10-04 MEDIUM 6.5 CVE-2021-22244 Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability … GitLab 13.12.9 / 14.0.7+ Fix from $1,6002021-08-25 MEDIUM 5.4 CVE-2021-22250 Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators cr… GitLab 13.12.9 / 14.0.7+ Fix from $1,6002021-08-25 MEDIUM 5.4 CVE-2021-22256 Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status GitLab 13.12.9 / 14.0.7+ Fix from $1,6002021-08-25 HIGH 8.8 CVE-2021-22236 Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability i… GitLab 14.1.2+ Fix from $1,9502021-08-25 MEDIUM 5.4 CVE-2021-22242EPSS 64% Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting v… GitLab 13.12.9 / 14.0.7+ Fix from $1,6002021-08-25 MEDIUM 6.5 CVE-2021-22252 A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which… GitLab 13.12.9 / 14.0.7+ Fix from $1,6002021-08-23 MEDIUM 5.4 CVE-2021-22253 Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments t… GitLab 13.12.9 / 14.0.7+ Fix from $1,6002021-08-23 MEDIUM 5.3 CVE-2021-22248 Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline info… GitLab 13.12.9 / 14.0.7+ Fix from $1,6002021-08-23 MEDIUM 6.5 CVE-2021-22246 A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of servic… GitLab 13.11.6 / 13.12.6+ Fix from $1,6002021-08-20 MEDIUM 5.4 CVE-2021-22238EPSS 72% An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature i… GitLab 13.12.9 / 14.0.7+ Fix from $1,6002021-08-20 MEDIUM 6.4 CVE-2021-22234 An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12… GitLab after 14.0.4 Fix from $1,6002021-08-05 MEDIUM 5.4 CVE-2021-22241 An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via … GitLab 14.0.7 / 14.1.2+ Fix from $1,6002021-08-05 MEDIUM 6.5 CVE-2021-22224 A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacke… GitLab 13.12.6 / 14.0.2+ Fix from $1,6002021-07-07 MEDIUM 5.4 CVE-2021-22225 Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability … GitLab 13.11.6 / 13.12.6+ Fix from $1,6002021-07-07 HIGH 7.2 CVE-2021-22230 Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and l… GitLab 13.11.6 / 13.12.6+ Fix from $1,9502021-07-07 MEDIUM 6.1 CVE-2021-22227 A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a v… GitLab 13.11.6 / 13.12.6+ Fix from $1,6002021-07-07 MEDIUM 6.5 CVE-2021-22228 An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions start… GitLab 13.11.6 / 13.12.6+ Fix from $1,6002021-07-06