Showing 2 vulnerabilities on this page for Community and Enterprise Editions

Signals CISA KEV Ransomware Nuclei
GitLab vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

CWE-918Dec 13, 2021
CVSS6.8v3.1EPSS35.6%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

CWE-20CWE-94CWE-95Apr 23, 20212 related artifacts
CVSS10.0v3.1EPSS99.7%PoCs34SignalsListed in CISA KEVKnown ransomware use2 Nuclei templatesSTIX