gitlab

1,383 tracked vulnerabilities.

CVE-2024-8650 MEDIUM
GitLab CE/EE <17.4.6-17.6.2 - Info Disclosure
Dec 16, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-8116 MEDIUM
GitLab CE/EE <17.4.6-17.6.2 - Info Disclosure
Dec 16, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-9387 MEDIUM
GitLab 11.8-17.4.5, 17.5-17.5.3, 17.6-17.6.1 - Open Redirect via Releases API Endpoint
Dec 12, 2024
CVSS 6.4
EPSS 0.00
CVE-2024-9367 MEDIUM
GitLab 13.9-17.4.5 17.5-17.5.3 17.6-17.6.1 - Denial of Service via Changelog Template Parsing
Dec 12, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-8647 MEDIUM
GitLab 15.2-17.4.6, 17.5 < 17.5.4, 17.6 < 17.6.2 - Anti-CSRF Token Leak via Harbor Integration
Dec 12, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-8233 HIGH
GitLab 9.4.0-17.4.5, 17.5.0-17.5.3, 17.6.0-17.6.1 - Denial of Service via Diff File Requests
Dec 12, 2024
CVSS 7.5
EPSS 0.01
CVE-2024-8179 MEDIUM
GitLab 17.3-17.4.5, 17.5-17.5.3, 17.6-17.6.1 - Cross-Site Scripting when CSP Disabled
Dec 12, 2024
CVSS 5.4
EPSS 0.01
CVE-2024-12570 MEDIUM
GitLab CE/EE <17.4.6-17.5.4-17.6.2 - Info Disclosure
Dec 12, 2024
CVSS 6.7
EPSS 0.00
CVE-2024-12292 MEDIUM
GitLab 11.0-17.4.5, 17.5-17.5.3, 17.6-17.6.1 - Sensitive Information Disclosure in GraphQL Logs
Dec 12, 2024
CVSS 4.0
EPSS 0.00
CVE-2024-11274 HIGH
GitLab 16.1-17.4.5, 17.5-17.5.3, 17.6-17.6.1 - Session Data Exfiltration via NEL Header Injection in k8s Proxy Response
Dec 12, 2024
CVSS 8.7
EPSS 0.00
CVE-2024-10043 LOW
GitLab EE <17.4.6-17.6.2 - Info Disclosure
Dec 12, 2024
CVSS 3.1
EPSS 0.00
CVE-2024-10240 MEDIUM
GitLab EE <17.3.7-17.5.2 - Info Disclosure
Nov 26, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-8237 MEDIUM
GitLab CE/EE <12.6-17.4.5, <17.5-17.5.3, <17.6-17.6.1 - DoS
Nov 26, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-8177 MEDIUM
GitLab CE/EE <17.4.5/<17.5.3/<17.6.1 - DoS
Nov 26, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-8114 HIGH
GitLab CE/EE <17.4.5-17.6.1 - Privilege Escalation
Nov 26, 2024
CVSS 8.2
EPSS 0.00
CVE-2024-11828 MEDIUM
GitLab 13.2.4-17.4.4, 17.5-17.5.2, 17.6-17.6.0 - Denial of Service via Crafted API Calls
Nov 26, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-11669 MEDIUM
GitLab CE/EE <17.4.5-17.6.1 - Info Disclosure
Nov 26, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-11668 MEDIUM
GitLab CE/EE <17.4.5-17.6.1 - Auth Bypass
Nov 26, 2024
CVSS 4.2
EPSS 0.00
CVE-2024-9633 LOW
GitLab CE/EE <17.4.2-17.5.4-17.6.2 - Info Disclosure
Nov 14, 2024
CVSS 3.1
EPSS 0.00
CVE-2024-8648 MEDIUM
GitLab 16.0.0-17.3.6, 17.4.0-17.4.3, 17.5.0-17.5.1 - Stored Cross-Site Scripting via Analytics Dashboard URL
Nov 14, 2024
CVSS 6.1
EPSS 0.03
CVE-2024-7404 MEDIUM
GitLab CE/EE <17.3.7-17.5.2 - Privilege Escalation
Nov 14, 2024
CVSS 6.8
EPSS 0.00
CVE-2024-9693 HIGH
GitLab 16.0-17.3.6, 17.4-17.4.3, 17.5-17.5.1 - Incorrect Authorization for Kubernetes Agent Access
Nov 14, 2024
CVSS 8.5
EPSS 0.00
CVE-2024-8180 MEDIUM
GitLab 17.3.0-17.3.6, 17.4.0-17.4.3, 17.5.0-17.5.1 - Cross-Site Scripting via Vulnerability Code Flow
Nov 14, 2024
CVSS 5.4
EPSS 0.03
CVE-2024-8312 HIGH
GitLab 15.10-17.3.6, 17.4-17.4.3, 17.5-17.5.1 - Cross-Site Scripting via Global Search Field on Diff View
Oct 24, 2024
CVSS 8.7
EPSS 0.02
CVE-2024-6826 MEDIUM
GitLab 11.2-17.3.5 17.4.0-17.4.2 17.5.0 - Denial of Service via Malicious XML Manifest Import
Oct 24, 2024
CVSS 6.5
EPSS 0.00