gitlab
1,383 tracked vulnerabilities.
CVE-2022-1821
MEDIUM
GitLab CE/EE <14.9.5-15.0.1 - Info Disclosure
Jun 06, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1783
LOW
GitLab CE/EE <14.9.5-15.0.1 - Privilege Escalation
Jun 06, 2022
CVSS 2.7
EPSS 0.00
CVE-2022-1423
HIGH
GitLab 1.0.2-14.8.5, 14.9.0-14.9.3, 14.10.0 - RCE via CI/CD Cache Poisoning
May 19, 2022
CVSS 7.1
EPSS 0.00
CVE-2022-1416
MEDIUM
GitLab 1.0.2-14.8.5, 14.9.0-14.9.3, 14.10.0 - Stored Cross-Site Scripting in Pipeline Error Messages
May 19, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1413
MEDIUM
GitLab 1.0.2-14.8.5, 14.9.0-14.9.3, 14.10.0 - Insufficiently Protected Credentials via Integration Properties
May 19, 2022
CVSS 5.4
EPSS 0.00
CVE-2022-1545
MEDIUM
Gitlab CE/EE <14.8.6-14.10.1 - Info Disclosure
May 11, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1510
MEDIUM
GitLab <14.8.6-14.9.4-14.10.1 - DoS
May 11, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-1460
MEDIUM
GitLab 9.2-14.8.5, 14.9-14.9.3, 14.10 - Incorrect Authorization for Scheduled Pipelines
May 11, 2022
CVSS 6.1
EPSS 0.00
CVE-2022-1433
LOW
GitLab 14.4-14.8.5, 14.9-14.9.3, 14.10 - Stored Cross-Site Scripting via Markdown Cache Invalidation Bypass
May 11, 2022
CVSS 2.6
EPSS 0.00
CVE-2022-1428
MEDIUM
GitLab < 14.8.6, 14.9 < 14.9.4, 14.10 < 14.10.1 - Allocation of Resources Without Limits or Throttling
May 11, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1426
LOW
GitLab 12.6-14.8.5, 14.9-14.9.3, 14.10 - Improper Authentication
May 11, 2022
CVSS 2.0
EPSS 0.00
CVE-2022-1406
MEDIUM
GitLab 8.12-14.8.5, 14.9.0-14.9.3, 14.10.0 - CI/CD Variable Exposure via Malicious Project Import
May 11, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-1352
MEDIUM
GitLab 11.0-14.8.6, 14.9-14.9.4, 14.10-14.10.1 - Insecure Direct Object Reference in Issue API
May 11, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-1124
MEDIUM
GitLab < 14.8.6, 14.9.0-14.9.4, 14.10.0 - Incorrect Authorization for Job Trace Log Access
May 11, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1431
MEDIUM
GitLab 12.10-14.8.5, 14.9-14.9.3, 14.10 - Denial of Service via PyPi API Endpoint
May 10, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1417
MEDIUM
GitLab 8.12-14.8.5, 14.9-14.9.3, 14.10 - Unauthenticated Project Wiki Access via CI Job
May 10, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-0477
MEDIUM
GitLab <14.5.4, <14.6.4, <14.7.1 - DoS
Apr 25, 2022
CVSS 4.9
EPSS 0.00
CVE-2022-1193
MEDIUM
GitLab 10.7-14.7.7, 14.8-14.8.5, 14.9-14.9.2 - Unauthenticated Improper Access Control via Merge Requests
Apr 11, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1157
LOW
GitLab < 14.7.7, 14.8 < 14.8.5, 14.9 < 14.9.2 - Sensitive Information Exposure via Exception Log
Apr 11, 2022
CVSS 2.6
EPSS 0.00
CVE-2022-1190
HIGH
GitLab 8.3-14.7.7, 14.8-14.8.5, 14.9-14.9.2 - Stored Cross-Site Scripting via Multi-Word Milestone References
Apr 04, 2022
CVSS 8.7
EPSS 0.01
CVE-2022-1189
LOW
GitLab CE/EE <14.7.7-14.9.2 - Info Disclosure
Apr 04, 2022
CVSS 3.1
EPSS 0.00
CVE-2022-1188
LOW
GitLab 12.1-14.7.6, 14.8-14.8.4, 14.9-14.9.1 - Server-Side Request Forgery via Repository Mirroring
Apr 04, 2022
CVSS 3.7
EPSS 0.00
CVE-2022-1185
MEDIUM
GitLab 10.0.0-14.7.7 14.8.0-14.8.5 14.9.0-14.9.2 - Denial of Service via RDoc File Rendering
Apr 04, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-1175
HIGH
GitLab 14.4-14.6.7 14.8-14.8.4 14.9-14.9.1 - Stored Cross-Site Scripting via Notes
Apr 04, 2022
CVSS 8.7
EPSS 0.10
CVE-2022-1174
MEDIUM
GitLab 13.7-14.7.6, 14.8-14.8.4, 14.9-14.9.1 - DoS via Crafted Input
Apr 04, 2022
CVSS 4.3
EPSS 0.00