GitLab Vulnerabilities and Affected Products
Vulnerabilities associated with Community and Enterprise Editions.
Products
Clear product- GitLab1,037 vulnerabilities
- GitLab CE/EE23 vulnerabilities
- GitLab Community and Enterprise Editions13 vulnerabilities
- GitLab EE10 vulnerabilities
- GitLab Runner6 vulnerabilities
- Community and Enterprise Editions2 vulnerabilities
- DAST2 vulnerabilities
- GitLab Community Edition2 vulnerabilities
- GitLab Enterprise Edition2 vulnerabilities
- gitlab-shell2 vulnerabilities
- gitlab-vscode-extension2 vulnerabilities
- DAST API scanner1 vulnerability
- Gitaly1 vulnerability
- GitLab AI Gateway1 vulnerability
- GitLab Community Edition and GitLab Enterprise Edition1 vulnerability
- GitLab DAST API scanner1 vulnerability
- GitLab Language Server1 vulnerability
- GitLab Pages1 vulnerability
- GitLab VSCode Fork1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-39935MEDIUM | GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) VulnerabilityAn issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API CWE-918Dec 13, 2021 | CVSS6.8v3.1 | EPSS35.6% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-22205CRITICAL | GitLab Community and Enterprise Editions Remote Code Execution VulnerabilityAn issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution. | CVSS10.0v3.1 | EPSS99.7% | PoCs34 | SignalsListed in CISA KEVKnown ransomware use2 Nuclei templates | STIX |