Exploit Database
149,701 exploits tracked across all sources.
GitLab 8.4-10.4 - Stored Cross-Site Scripting in Merge Request Changes Tab
GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.
CVSS 6.1
GitLab 8.3-10.x - Server-Side Request Forgery in Services and Webhooks
GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.
CVSS 6.5
GitLab 8.3-10.x - Server-Side Request Forgery in Services and Webhooks
GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.
CVSS 6.5
GitLab 8.9.0-9.5.9 - Remote Code Execution via Insecure Temporary File in Project Import
Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.
CVSS 7.8
GitLab 8.12.0-11.4.12 11.5.0-11.5.5 11.6.0 - Missing Authorization
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
CVSS 6.3
GitLab 11.x < 11.4.13, 11.5.x < 11.5.6, 11.6.x < 11.6.1 - Server-Side Request Forgery
An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.
CVSS 7.2
GitLab 8.10.0-11.4.12, 11.5.0-11.5.5, 11.6.0 - Incorrect Authorization
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
CVSS 4.3
GitLab < 11.4.13, 11.5.x < 11.5.6, 11.6.x < 11.6.1 - Server-Side Request Forgery
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.
CVSS 5.0
GitLab 11.2.x-11.4.x < 11.4.13, 11.5.x < 11.5.6, 11.6.x < 11.6.1 - Cross-Site Scripting
An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.
CVSS 5.4
GitLab 11.3.0-11.4.12, 11.5.0-11.5.5, 11.6.0 - Information Exposure
An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.
CVSS 5.3
GitLab 8.4.0-11.4.12 11.5.0-11.5.5 11.6.0 - Incorrect Authorization
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
CVSS 7.5
GitLab 8.17.0-11.4.12 11.5.0-11.5.5 11.6.0 - Incorrect Authorization
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
CVSS 4.3
GitLab 11.3.0-11.4.12, 11.5.0-11.5.5, 11.6.0 - Cross-Site Scripting
An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.
CVSS 5.4
GitLab 11.2.0-11.4.12, 11.5.0-11.5.5, 11.6.0 - Cross-Site Scripting
An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.
CVSS 5.4
GitLab 9.3.0-11.4.12, 11.5.0-11.5.5, 11.6.0 - Information Exposure
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.
CVSS 4.3
GitLab <11.3.13-11.5.4 - Info Disclosure
GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorrect Access Control.
CVSS 7.5
GitLab <11.3.12-11.5.3 - Path Traversal
GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API.
CVSS 7.5
GitLab EE <11.3.11-11.5.1 - Info Disclosure
GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups.
CVSS 7.5
GitLab <11.5.1-11.3.11 - Info Disclosure
All versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11 do not send an email to the old email address when an email address change is made.
CVSS 5.3
GitLab 11.5.0 - Stored Cross-Site Scripting in Operations Page
GitLab EE version 11.5 is vulnerable to a persistent XSS vulnerability in the Operations page. This is fixed in 11.5.1.
CVSS 5.4
GitLab EE <11.5.1 - Info Disclosure
GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the Jaeger Tracing Operations page.
CVSS 6.5
Gitlab CE/EE <11.3.11-11.5.1 - Info Disclosure
Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.
CVSS 5.3
GitLab CE/EE <11.3.11-11.4.8-11.5.1 - Info Disclosure
GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the issue was made Confidential.
CVSS 8.1
GitLab CE/EE <11.3.11-11.5.1 - Info Disclosure
GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue.
CVSS 4.3
GitLab 7.6-11.3.10, 11.4-11.4.7, 11.5 - Cross-Site Scripting in OAuth Authorization Page
GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in the OAuth authorization page.
CVSS 5.4
By Source