gitlab
1,383 tracked vulnerabilities.
CVE-2024-9164
CRITICAL
GitLab 12.5.0-17.2.8, 17.3.0-17.3.4, 17.4.0-17.4.1 - Unauthenticated Pipeline Execution on Arbitrary Branches
Oct 11, 2024
CVSS 9.6
EPSS 0.00
CVE-2024-8970
HIGH
GitLab 11.6-17.2.8, 17.3-17.3.4, 17.4-17.4.1 - Incorrect Authorization
Oct 11, 2024
CVSS 8.2
EPSS 0.00
CVE-2024-5005
MEDIUM
GitLab EE/CE <17.2.9-17.4.2 - Info Disclosure
Oct 11, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-6530
HIGH
GitLab <17.2.9/<17.3.5/<17.4.2 - XSS
Oct 10, 2024
CVSS 7.3
EPSS 0.01
CVE-2024-9623
MEDIUM
GitLab 8.16-17.2.8, 17.3-17.3.4, 17.4-17.4.1 - Incorrect Authorization for Deploy Key Push to Archived Repository
Oct 10, 2024
CVSS 4.9
EPSS 0.00
CVE-2024-9596
LOW
GitLab EE <17.2.9, <17.3.5, <17.4.2 - Info Disclosure
Oct 10, 2024
CVSS 3.7
EPSS 0.00
CVE-2024-8977
HIGH
GitLab 15.10-17.2.8, 17.3-17.3.4, 17.4-17.4.1 - Server-Side Request Forgery via Product Analytics Dashboard
Oct 10, 2024
CVSS 8.2
EPSS 0.00
CVE-2024-8974
LOW
GitLab 15.6-17.2.7, 17.3-17.3.3, 17.4-17.4.0 - Unauthenticated Private Project Path Disclosure
Sep 26, 2024
CVSS 2.6
EPSS 0.00
CVE-2024-4099
LOW
GitLab EE <17.2.8-17.3.4-17.4.1 - Info Disclosure
Sep 26, 2024
CVSS 3.1
EPSS 0.00
CVE-2024-4278
MEDIUM
GitLab EE <17.2.8, <17.3.4, <17.4.1 - Info Disclosure
Sep 26, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-6685
LOW
GitLab CE/EE <17.1.7-17.3.2 - Info Disclosure
Sep 16, 2024
CVSS 3.1
EPSS 0.00
CVE-2024-4283
MEDIUM
GitLab EE <17.1.7-17.3.2 - Open Redirect
Sep 16, 2024
CVSS 6.4
EPSS 0.00
CVE-2024-8641
MEDIUM
GitLab CE/EE <17.1.7-17.2.5-17.3.2 - Info Disclosure
Sep 12, 2024
CVSS 6.7
EPSS 0.00
CVE-2024-8311
MEDIUM
GitLab EE <17.2.5-17.3.2 - Auth Bypass
Sep 12, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-6678
CRITICAL
GitLab CE/EE <17.1.7-17.3.2 - Privilege Escalation
Sep 12, 2024
CVSS 9.9
EPSS 0.00
CVE-2024-4472
MEDIUM
GitLab CE/EE <17.1.7-17.2.5-17.3.2 - Info Disclosure
Sep 12, 2024
CVSS 4.0
EPSS 0.00
CVE-2024-8754
MEDIUM
GitLab EE/CE <17.1.7-17.3.2 - Info Disclosure
Sep 12, 2024
CVSS 6.4
EPSS 0.00
CVE-2024-8640
HIGH
GitLab EE <17.1.7-17.3.2 - Command Injection
Sep 12, 2024
CVSS 8.5
EPSS 0.00
CVE-2024-8635
HIGH
GitLab 16.8-17.1.6, 17.2-17.2.4, 17.3-17.3.1 - Server-Side Request Forgery via Maven Dependency Proxy URL
Sep 12, 2024
CVSS 7.7
EPSS 0.00
CVE-2024-8631
MEDIUM
GitLab 16.6-17.1.6, 17.2-17.2.4, 17.3-17.3.1 - Privilege Escalation via Admin Group Member Role
Sep 12, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-8124
HIGH
GitLab 16.4-17.1.6, 17.2-17.2.4, 17.3-17.3.1 - Denial of Service via POST Request
Sep 12, 2024
CVSS 7.5
EPSS 0.05
CVE-2024-6446
LOW
GitLab <17.1.7-17.2.5-17.3.2 - CSRF
Sep 12, 2024
CVSS 3.5
EPSS 0.00
CVE-2024-6389
MEDIUM
GitLab-CE/EE <17.1.7, <17.2.5, <17.3.2 - Info Disclosure
Sep 12, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-5435
MEDIUM
GitLab 15.10.0-17.1.6, 17.2.0-17.2.4, 17.3.0-17.3.1 - Sensitive Information Disclosure
Sep 12, 2024
CVSS 4.5
EPSS 0.00
CVE-2024-4660
MEDIUM
GitLab 11.2.0-17.1.6, 17.2.0-17.2.4, 17.3.0-17.3.1 - Private Project Source Code Exposure via Group Templates
Sep 12, 2024
CVSS 6.5
EPSS 0.00