Vulnerability index

Browse CVEs

1,035 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2021-22188 An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorise… GitLab 13.6.7 / 13.7.7+ Fix from $1,6002021-03-03 HIGH 7.5 CVE-2021-22166 An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method GitLab 13.7.2+ Fix from $1,9502021-01-15 HIGH 7.5 CVE-2021-22167 An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have … GitLab 13.5.6 / 13.6.4+ Fix from $1,9502021-01-15 MEDIUM 6.5 CVE-2021-22168 A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8. GitLab 13.5.6 / 13.6.4+ Fix from $1,6002021-01-15 MEDIUM 6.5 CVE-2021-22171 Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click … GitLab 13.5.6 / 13.6.4+ Fix from $1,6002021-01-15 MEDIUM 6.5 CVE-2020-26414 An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes exe… GitLab 13.5.6 / 13.6.4+ Fix from $1,6002021-01-15 MEDIUM 5.3 CVE-2020-26408 A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows a… GitLab 13.4.7 / 13.5.5+ Fix from $1,6002020-12-11 MEDIUM 5.3 CVE-2020-26413EPSS 35% An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in u… GitLab 13.6.2+ Fix from $1,6002020-12-11 MEDIUM 5.3 CVE-2020-26417 Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6… GitLab 13.4.7 / 13.5.5+ Fix from $1,6002020-12-11 MEDIUM 6.5 CVE-2020-26409 A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource b… GitLab 13.4.7 / 13.5.5+ Fix from $1,6002020-12-11 MEDIUM 5.4 CVE-2020-26407 A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cro… GitLab 13.4.7 / 13.5.5+ Fix from $1,6002020-12-10 HIGH 8.2 CVE-2020-13356 An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protectio… GitLab 13.3.9 / 13.4.5+ Fix from $1,9502020-11-19 HIGH 7.6 CVE-2020-13359 The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to ove… GitLab 13.3.9 / 13.4.5+ Fix from $1,9502020-11-19 HIGH 8.1 CVE-2020-13355 An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker … GitLab 13.3.9 / 13.4.5+ Fix from $1,9502020-11-19 HIGH 7.1 CVE-2020-26405 Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary loca… GitLab 13.3.9 / 13.4.5+ Fix from $1,9502020-11-17 MEDIUM 5.7 CVE-2020-13348 An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a br… GitLab 13.3.9 / 13.4.5+ Fix from $1,6002020-11-17 MEDIUM 6.5 CVE-2020-13351 Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pip… GitLab 13.3.9 / 13.4.5+ Fix from $1,6002020-11-17 MEDIUM 5.5 CVE-2020-13358 A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected … GitLab 13.3.9 / 13.4.5+ Fix from $1,6002020-11-17 MEDIUM 5.3 CVE-2020-13352 Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions… GitLab 13.3.9 / 13.4.5+ Fix from $1,6002020-11-17 MEDIUM 5.3 CVE-2020-26406 Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through … GitLab 13.3.9 / 13.4.5+ Fix from $1,6002020-11-17 HIGH 7.5 CVE-2020-13327 An issue has been discovered in GitLab Runner affecting all versions starting from 13.4.0 before 13.4.2, all versions starting from 13.3.0 before 13.… Runner 13.2.10 / 13.3.7+ Fix from $1,9502020-10-22 HIGH 8.7 CVE-2020-13340EPSS 69% An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log GitLab 13.2.10 / 13.3.7+ Fix from $1,9502020-10-08 MEDIUM 6.5 CVE-2020-13339 An issue has been discovered in GitLab affecting all versions before 13.2.10, 13.3.7 and 13.4.2: XSS in SVG File Preview. Overall impact is limited d… GitLab 13.2.10 / 13.3.7+ Fix from $1,6002020-10-08 CRITICAL 9.1 CVE-2020-13347 A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Win… GitLab 13.2.4 / 13.3.2+ Fix from $2,3002020-10-07 HIGH 7.5 CVE-2020-13334 In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentia… GitLab 13.2.10 / 13.3.7+ Fix from $1,9502020-10-07 MEDIUM 6.5 CVE-2020-13346 Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access con… GitLab 13.2.10 / 13.3.7+ Fix from $1,6002020-10-07 HIGH 8.8 CVE-2020-13343 An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template GitLab after 13.4.3 Fix from $1,9502020-10-06 MEDIUM 5.4 CVE-2020-13345 An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes GitLab 13.2.10 / 13.3.7+ Fix from $1,6002020-10-06 MEDIUM 5.4 CVE-2020-13338 An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discover… GitLab 12.10.13 / 13.0.8+ Fix from $1,6002020-10-02 MEDIUM 5.4 CVE-2020-13331 An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges. GitLab 12.10.13+ Fix from $1,6002020-09-30