GitLab Vulnerabilities and Affected Products
Vulnerabilities associated with GitLab Community and Enterprise Editions.
Products
Clear product- GitLab1,037 vulnerabilities
- GitLab CE/EE23 vulnerabilities
- GitLab Community and Enterprise Editions13 vulnerabilities
- GitLab EE10 vulnerabilities
- GitLab Runner6 vulnerabilities
- Community and Enterprise Editions2 vulnerabilities
- DAST2 vulnerabilities
- GitLab Community Edition2 vulnerabilities
- GitLab Enterprise Edition2 vulnerabilities
- gitlab-shell2 vulnerabilities
- gitlab-vscode-extension2 vulnerabilities
- DAST API scanner1 vulnerability
- Gitaly1 vulnerability
- GitLab AI Gateway1 vulnerability
- GitLab Community Edition and GitLab Enterprise Edition1 vulnerability
- GitLab DAST API scanner1 vulnerability
- GitLab Language Server1 vulnerability
- GitLab Pages1 vulnerability
- GitLab VSCode Fork1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2017-0920MEDIUM | GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance. | CVSS4.3v3.0 | EPSS0.904% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-0916CRITICAL | Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution. | CVSS9.8v3.0 | EPSS5.62% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-0914HIGH | Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database. CWE-89Mar 21, 2018 | CVSS7.5v3.0 | EPSS1.39% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-0926HIGH | Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login. | CVSS8.8v3.0 | EPSS1.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-0927MEDIUM | Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users. | CVSS6.5v3.0 | EPSS0.807% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-3710HIGH | Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution. | CVSS7.8v3.1 | EPSS2.86% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-0922HIGH | Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object. | CVSS7.5v3.0 | EPSS1.36% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-0924MEDIUM | Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in persistent cross site scripting. CWE-79Mar 21, 2018 | CVSS6.1v3.0 | EPSS0.771% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-0923MEDIUM | Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting. CWE-79Mar 21, 2018 | CVSS6.1v3.0 | EPSS0.771% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-0918HIGH | Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution. | CVSS8.8v3.0 | EPSS4.54% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-0915CRITICAL | Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution. | CVSS9.8v3.0 | EPSS5.62% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-0917MEDIUM | Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting. | CVSS6.1v3.0 | EPSS1.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-0925HIGH | Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password. | CVSS7.2v3.0 | EPSS0.885% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |