gitlab
1,383 tracked vulnerabilities.
CVE-2024-8650
MEDIUM
GitLab CE/EE <17.4.6-17.6.2 - Info Disclosure
Dec 16, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-8116
MEDIUM
GitLab CE/EE <17.4.6-17.6.2 - Info Disclosure
Dec 16, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-9387
MEDIUM
GitLab 11.8-17.4.5, 17.5-17.5.3, 17.6-17.6.1 - Open Redirect via Releases API Endpoint
Dec 12, 2024
CVSS 6.4
EPSS 0.00
CVE-2024-9367
MEDIUM
GitLab 13.9-17.4.5 17.5-17.5.3 17.6-17.6.1 - Denial of Service via Changelog Template Parsing
Dec 12, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-8647
MEDIUM
GitLab 15.2-17.4.6, 17.5 < 17.5.4, 17.6 < 17.6.2 - Anti-CSRF Token Leak via Harbor Integration
Dec 12, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-8233
HIGH
GitLab 9.4.0-17.4.5, 17.5.0-17.5.3, 17.6.0-17.6.1 - Denial of Service via Diff File Requests
Dec 12, 2024
CVSS 7.5
EPSS 0.01
CVE-2024-8179
MEDIUM
GitLab 17.3-17.4.5, 17.5-17.5.3, 17.6-17.6.1 - Cross-Site Scripting when CSP Disabled
Dec 12, 2024
CVSS 5.4
EPSS 0.01
CVE-2024-12570
MEDIUM
GitLab CE/EE <17.4.6-17.5.4-17.6.2 - Info Disclosure
Dec 12, 2024
CVSS 6.7
EPSS 0.00
CVE-2024-12292
MEDIUM
GitLab 11.0-17.4.5, 17.5-17.5.3, 17.6-17.6.1 - Sensitive Information Disclosure in GraphQL Logs
Dec 12, 2024
CVSS 4.0
EPSS 0.00
CVE-2024-11274
HIGH
GitLab 16.1-17.4.5, 17.5-17.5.3, 17.6-17.6.1 - Session Data Exfiltration via NEL Header Injection in k8s Proxy Response
Dec 12, 2024
CVSS 8.7
EPSS 0.00
CVE-2024-10043
LOW
GitLab EE <17.4.6-17.6.2 - Info Disclosure
Dec 12, 2024
CVSS 3.1
EPSS 0.00
CVE-2024-10240
MEDIUM
GitLab EE <17.3.7-17.5.2 - Info Disclosure
Nov 26, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-8237
MEDIUM
GitLab CE/EE <12.6-17.4.5, <17.5-17.5.3, <17.6-17.6.1 - DoS
Nov 26, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-8177
MEDIUM
GitLab CE/EE <17.4.5/<17.5.3/<17.6.1 - DoS
Nov 26, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-8114
HIGH
GitLab CE/EE <17.4.5-17.6.1 - Privilege Escalation
Nov 26, 2024
CVSS 8.2
EPSS 0.00
CVE-2024-11828
MEDIUM
GitLab 13.2.4-17.4.4, 17.5-17.5.2, 17.6-17.6.0 - Denial of Service via Crafted API Calls
Nov 26, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-11669
MEDIUM
GitLab CE/EE <17.4.5-17.6.1 - Info Disclosure
Nov 26, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-11668
MEDIUM
GitLab CE/EE <17.4.5-17.6.1 - Auth Bypass
Nov 26, 2024
CVSS 4.2
EPSS 0.00
CVE-2024-9633
LOW
GitLab CE/EE <17.4.2-17.5.4-17.6.2 - Info Disclosure
Nov 14, 2024
CVSS 3.1
EPSS 0.00
CVE-2024-8648
MEDIUM
GitLab 16.0.0-17.3.6, 17.4.0-17.4.3, 17.5.0-17.5.1 - Stored Cross-Site Scripting via Analytics Dashboard URL
Nov 14, 2024
CVSS 6.1
EPSS 0.03
CVE-2024-7404
MEDIUM
GitLab CE/EE <17.3.7-17.5.2 - Privilege Escalation
Nov 14, 2024
CVSS 6.8
EPSS 0.00
CVE-2024-9693
HIGH
GitLab 16.0-17.3.6, 17.4-17.4.3, 17.5-17.5.1 - Incorrect Authorization for Kubernetes Agent Access
Nov 14, 2024
CVSS 8.5
EPSS 0.00
CVE-2024-8180
MEDIUM
GitLab 17.3.0-17.3.6, 17.4.0-17.4.3, 17.5.0-17.5.1 - Cross-Site Scripting via Vulnerability Code Flow
Nov 14, 2024
CVSS 5.4
EPSS 0.03
CVE-2024-8312
HIGH
GitLab 15.10-17.3.6, 17.4-17.4.3, 17.5-17.5.1 - Cross-Site Scripting via Global Search Field on Diff View
Oct 24, 2024
CVSS 8.7
EPSS 0.02
CVE-2024-6826
MEDIUM
GitLab 11.2-17.3.5 17.4.0-17.4.2 17.5.0 - Denial of Service via Malicious XML Manifest Import
Oct 24, 2024
CVSS 6.5
EPSS 0.00