gitlab

1,383 tracked vulnerabilities.

CVE-2022-1821 MEDIUM
GitLab CE/EE <14.9.5-15.0.1 - Info Disclosure
Jun 06, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1783 LOW
GitLab CE/EE <14.9.5-15.0.1 - Privilege Escalation
Jun 06, 2022
CVSS 2.7
EPSS 0.00
CVE-2022-1423 HIGH
GitLab 1.0.2-14.8.5, 14.9.0-14.9.3, 14.10.0 - RCE via CI/CD Cache Poisoning
May 19, 2022
CVSS 7.1
EPSS 0.00
CVE-2022-1416 MEDIUM
GitLab 1.0.2-14.8.5, 14.9.0-14.9.3, 14.10.0 - Stored Cross-Site Scripting in Pipeline Error Messages
May 19, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1413 MEDIUM
GitLab 1.0.2-14.8.5, 14.9.0-14.9.3, 14.10.0 - Insufficiently Protected Credentials via Integration Properties
May 19, 2022
CVSS 5.4
EPSS 0.00
CVE-2022-1545 MEDIUM
Gitlab CE/EE <14.8.6-14.10.1 - Info Disclosure
May 11, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1510 MEDIUM
GitLab <14.8.6-14.9.4-14.10.1 - DoS
May 11, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-1460 MEDIUM
GitLab 9.2-14.8.5, 14.9-14.9.3, 14.10 - Incorrect Authorization for Scheduled Pipelines
May 11, 2022
CVSS 6.1
EPSS 0.00
CVE-2022-1433 LOW
GitLab 14.4-14.8.5, 14.9-14.9.3, 14.10 - Stored Cross-Site Scripting via Markdown Cache Invalidation Bypass
May 11, 2022
CVSS 2.6
EPSS 0.00
CVE-2022-1428 MEDIUM
GitLab < 14.8.6, 14.9 < 14.9.4, 14.10 < 14.10.1 - Allocation of Resources Without Limits or Throttling
May 11, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1426 LOW
GitLab 12.6-14.8.5, 14.9-14.9.3, 14.10 - Improper Authentication
May 11, 2022
CVSS 2.0
EPSS 0.00
CVE-2022-1406 MEDIUM
GitLab 8.12-14.8.5, 14.9.0-14.9.3, 14.10.0 - CI/CD Variable Exposure via Malicious Project Import
May 11, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-1352 MEDIUM
GitLab 11.0-14.8.6, 14.9-14.9.4, 14.10-14.10.1 - Insecure Direct Object Reference in Issue API
May 11, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-1124 MEDIUM
GitLab < 14.8.6, 14.9.0-14.9.4, 14.10.0 - Incorrect Authorization for Job Trace Log Access
May 11, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1431 MEDIUM
GitLab 12.10-14.8.5, 14.9-14.9.3, 14.10 - Denial of Service via PyPi API Endpoint
May 10, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1417 MEDIUM
GitLab 8.12-14.8.5, 14.9-14.9.3, 14.10 - Unauthenticated Project Wiki Access via CI Job
May 10, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-0477 MEDIUM
GitLab <14.5.4, <14.6.4, <14.7.1 - DoS
Apr 25, 2022
CVSS 4.9
EPSS 0.00
CVE-2022-1193 MEDIUM
GitLab 10.7-14.7.7, 14.8-14.8.5, 14.9-14.9.2 - Unauthenticated Improper Access Control via Merge Requests
Apr 11, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1157 LOW
GitLab < 14.7.7, 14.8 < 14.8.5, 14.9 < 14.9.2 - Sensitive Information Exposure via Exception Log
Apr 11, 2022
CVSS 2.6
EPSS 0.00
CVE-2022-1190 HIGH
GitLab 8.3-14.7.7, 14.8-14.8.5, 14.9-14.9.2 - Stored Cross-Site Scripting via Multi-Word Milestone References
Apr 04, 2022
CVSS 8.7
EPSS 0.01
CVE-2022-1189 LOW
GitLab CE/EE <14.7.7-14.9.2 - Info Disclosure
Apr 04, 2022
CVSS 3.1
EPSS 0.00
CVE-2022-1188 LOW
GitLab 12.1-14.7.6, 14.8-14.8.4, 14.9-14.9.1 - Server-Side Request Forgery via Repository Mirroring
Apr 04, 2022
CVSS 3.7
EPSS 0.00
CVE-2022-1185 MEDIUM
GitLab 10.0.0-14.7.7 14.8.0-14.8.5 14.9.0-14.9.2 - Denial of Service via RDoc File Rendering
Apr 04, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-1175 HIGH
GitLab 14.4-14.6.7 14.8-14.8.4 14.9-14.9.1 - Stored Cross-Site Scripting via Notes
Apr 04, 2022
CVSS 8.7
EPSS 0.10
CVE-2022-1174 MEDIUM
GitLab 13.7-14.7.6, 14.8-14.8.4, 14.9-14.9.1 - DoS via Crafted Input
Apr 04, 2022
CVSS 4.3
EPSS 0.00