gitlab
1,383 tracked vulnerabilities.
CVE-2022-2992
CRITICAL
GitLab GitHub Repo Import Deserialization RCE
Oct 17, 2022
CVSS 9.9
EPSS 0.91
CVE-2022-2931
HIGH
GitLab < 15.1.6, 15.2-15.2.4, 15.3-15.3.2 - Denial of Service via Malformed Issue Description
Oct 17, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-2908
MEDIUM
GitLab 10.7-15.1.4, 15.2-15.2.2, 15.3 - Denial of Service via Commit Message Field
Oct 17, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-2884
CRITICAL
GitLab CE/EE <15.1.5-15.3.1 - Authenticated RCE
Oct 17, 2022
CVSS 9.9
EPSS 0.30
CVE-2022-2865
HIGH
GitLab CE/EE <15.1.6, <15.2.4, <15.3.2 - XSS
Oct 17, 2022
CVSS 7.3
EPSS 0.00
CVE-2022-2630
MEDIUM
GitLab CE/EE <15.2.4-15.3.2 - Info Disclosure
Oct 17, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-2592
MEDIUM
GitLab < 15.1.6, 15.2 < 15.2.4, 15.3 < 15.3.2 - Authenticated Denial of Service via Snippet Description Length
Oct 17, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-2533
MEDIUM
GitLab <15.1.6-15.3.2 - Auth Bypass
Oct 17, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-2527
HIGH
GitLab CE/EE <15.1.6-15.3.2 - Authenticated XSS
Oct 17, 2022
CVSS 7.3
EPSS 0.00
CVE-2022-2455
MEDIUM
GitLab 10.0.0-15.1.5, 15.2.0-15.2.3, 15.3.0-15.3.1 - Authenticated Resource Exhaustion via Malicious Project Import
Oct 17, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-2428
MEDIUM
GitLab < 15.1.6, 15.2-15.2.4, 15.3-15.3.2 - Server-Side Request Forgery via Jupyter Notebook Viewer
Oct 17, 2022
CVSS 6.4
EPSS 0.00
CVE-2022-2539
MEDIUM
GitLab CE/EE <15.0.5-15.2.1 - Info Disclosure
Aug 05, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-2534
LOW
GitLab CE/EE <15.0.5-15.2.1 - Info Disclosure
Aug 05, 2022
CVSS 2.2
EPSS 0.00
CVE-2022-2531
MEDIUM
GitLab EE <15.0.5-15.2.1 - Path Traversal
Aug 05, 2022
CVSS 5.3
EPSS 0.01
CVE-2022-2512
MEDIUM
GitLab CE/EE <15.0.5-15.2.1 - Info Disclosure
Aug 05, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-2501
MEDIUM
GitLab EE <15.0.5-15.2.1 - Auth Bypass
Aug 05, 2022
CVSS 5.9
EPSS 0.00
CVE-2022-2500
MEDIUM
GitLab < 15.0.5, 15.1 < 15.1.4, 15.2 < 15.2.1 - Stored Cross-Site Scripting in Job Error Messages
Aug 05, 2022
CVSS 4.4
EPSS 0.00
CVE-2022-2499
LOW
GitLab 13.10.0-15.0.4, 15.1.0-15.1.3, 15.2.0 - Authorization Bypass via Jira Integration
Aug 05, 2022
CVSS 3.5
EPSS 0.00
CVE-2022-2498
MEDIUM
GitLab 12.8-15.0.4, 15.1-15.1.3, 15.2 - Improper Privilege Management in Pipeline Subscriptions
Aug 05, 2022
CVSS 6.4
EPSS 0.00
CVE-2022-2497
HIGH
GitLab CE/EE <15.0.5, <15.1.4, <15.2.1 - Info Disclosure
Aug 05, 2022
CVSS 8.5
EPSS 0.02
CVE-2022-2459
LOW
GitLab < 15.0.5, 15.1 < 15.1.4, 15.2 < 15.2.1 - Missing Authorization for Email Invited Members
Aug 05, 2022
CVSS 2.7
EPSS 0.00
CVE-2022-2456
MEDIUM
GitLab CE/EE <15.0.5, <15.1.4, <15.2.1 - Info Disclosure
Aug 05, 2022
CVSS 4.9
EPSS 0.00
CVE-2022-2417
MEDIUM
GitLab 12.10-15.0.4, 15.1-15.1.3, 15.2-15.2.0 - Authenticated Supply Chain Attack via Branch Name Spoofing
Aug 05, 2022
CVSS 6.2
EPSS 0.00
CVE-2022-2326
MEDIUM
GitLab CE/EE <15.0.5, <15.1.4, <15.2.1 - Info Disclosure
Aug 05, 2022
CVSS 6.4
EPSS 0.00
CVE-2022-2307
LOW
GitLab CE/EE <15.0.5-15.2.1 - Info Disclosure
Aug 05, 2022
CVSS 3.5
EPSS 0.00