gitlab

1,383 tracked vulnerabilities.

CVE-2024-9164 CRITICAL
GitLab 12.5.0-17.2.8, 17.3.0-17.3.4, 17.4.0-17.4.1 - Unauthenticated Pipeline Execution on Arbitrary Branches
Oct 11, 2024
CVSS 9.6
EPSS 0.00
CVE-2024-8970 HIGH
GitLab 11.6-17.2.8, 17.3-17.3.4, 17.4-17.4.1 - Incorrect Authorization
Oct 11, 2024
CVSS 8.2
EPSS 0.00
CVE-2024-5005 MEDIUM
GitLab EE/CE <17.2.9-17.4.2 - Info Disclosure
Oct 11, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-6530 HIGH
GitLab <17.2.9/<17.3.5/<17.4.2 - XSS
Oct 10, 2024
CVSS 7.3
EPSS 0.01
CVE-2024-9623 MEDIUM
GitLab 8.16-17.2.8, 17.3-17.3.4, 17.4-17.4.1 - Incorrect Authorization for Deploy Key Push to Archived Repository
Oct 10, 2024
CVSS 4.9
EPSS 0.00
CVE-2024-9596 LOW
GitLab EE <17.2.9, <17.3.5, <17.4.2 - Info Disclosure
Oct 10, 2024
CVSS 3.7
EPSS 0.00
CVE-2024-8977 HIGH
GitLab 15.10-17.2.8, 17.3-17.3.4, 17.4-17.4.1 - Server-Side Request Forgery via Product Analytics Dashboard
Oct 10, 2024
CVSS 8.2
EPSS 0.00
CVE-2024-8974 LOW
GitLab 15.6-17.2.7, 17.3-17.3.3, 17.4-17.4.0 - Unauthenticated Private Project Path Disclosure
Sep 26, 2024
CVSS 2.6
EPSS 0.00
CVE-2024-4099 LOW
GitLab EE <17.2.8-17.3.4-17.4.1 - Info Disclosure
Sep 26, 2024
CVSS 3.1
EPSS 0.00
CVE-2024-4278 MEDIUM
GitLab EE <17.2.8, <17.3.4, <17.4.1 - Info Disclosure
Sep 26, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-6685 LOW
GitLab CE/EE <17.1.7-17.3.2 - Info Disclosure
Sep 16, 2024
CVSS 3.1
EPSS 0.00
CVE-2024-4283 MEDIUM
GitLab EE <17.1.7-17.3.2 - Open Redirect
Sep 16, 2024
CVSS 6.4
EPSS 0.00
CVE-2024-8641 MEDIUM
GitLab CE/EE <17.1.7-17.2.5-17.3.2 - Info Disclosure
Sep 12, 2024
CVSS 6.7
EPSS 0.00
CVE-2024-8311 MEDIUM
GitLab EE <17.2.5-17.3.2 - Auth Bypass
Sep 12, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-6678 CRITICAL
GitLab CE/EE <17.1.7-17.3.2 - Privilege Escalation
Sep 12, 2024
CVSS 9.9
EPSS 0.00
CVE-2024-4472 MEDIUM
GitLab CE/EE <17.1.7-17.2.5-17.3.2 - Info Disclosure
Sep 12, 2024
CVSS 4.0
EPSS 0.00
CVE-2024-8754 MEDIUM
GitLab EE/CE <17.1.7-17.3.2 - Info Disclosure
Sep 12, 2024
CVSS 6.4
EPSS 0.00
CVE-2024-8640 HIGH
GitLab EE <17.1.7-17.3.2 - Command Injection
Sep 12, 2024
CVSS 8.5
EPSS 0.00
CVE-2024-8635 HIGH
GitLab 16.8-17.1.6, 17.2-17.2.4, 17.3-17.3.1 - Server-Side Request Forgery via Maven Dependency Proxy URL
Sep 12, 2024
CVSS 7.7
EPSS 0.00
CVE-2024-8631 MEDIUM
GitLab 16.6-17.1.6, 17.2-17.2.4, 17.3-17.3.1 - Privilege Escalation via Admin Group Member Role
Sep 12, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-8124 HIGH
GitLab 16.4-17.1.6, 17.2-17.2.4, 17.3-17.3.1 - Denial of Service via POST Request
Sep 12, 2024
CVSS 7.5
EPSS 0.05
CVE-2024-6446 LOW
GitLab <17.1.7-17.2.5-17.3.2 - CSRF
Sep 12, 2024
CVSS 3.5
EPSS 0.00
CVE-2024-6389 MEDIUM
GitLab-CE/EE <17.1.7, <17.2.5, <17.3.2 - Info Disclosure
Sep 12, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-5435 MEDIUM
GitLab 15.10.0-17.1.6, 17.2.0-17.2.4, 17.3.0-17.3.1 - Sensitive Information Disclosure
Sep 12, 2024
CVSS 4.5
EPSS 0.00
CVE-2024-4660 MEDIUM
GitLab 11.2.0-17.1.6, 17.2.0-17.2.4, 17.3.0-17.3.1 - Private Project Source Code Exposure via Group Templates
Sep 12, 2024
CVSS 6.5
EPSS 0.00