gitlab
1,383 tracked vulnerabilities.
CVE-2021-39898
LOW
GitLab 10.6.0-14.1.6 - Exposure of Sensitive Information via Project Export
Nov 05, 2021
CVSS 3.7
EPSS 0.00
CVE-2021-39897
LOW
GitLab CE/EE >=10.5 - Info Disclosure
Nov 05, 2021
CVSS 2.6
EPSS 0.00
CVE-2021-39895
MEDIUM
GitLab 8.0.0-14.1.7 - Information Disclosure via Imported Pipeline Schedules
Nov 05, 2021
CVSS 6.0
EPSS 0.00
CVE-2021-22260
HIGH
GitLab 13.7-14.0.8, 14.1-14.1.3, 14.2-14.2.1 - Stored Cross-Site Scripting in DataDog Integration
Nov 05, 2021
CVSS 7.7
EPSS 0.00
CVE-2021-39914
LOW
GitLab 8.13-14.2.5 14.3.0-14.3.3 14.4.0 - Regular Expression Denial of Service via Username Provisioning
Nov 04, 2021
CVSS 3.1
EPSS 0.00
CVE-2021-39903
MEDIUM
GitLab CE/EE <13.0 - Privilege Escalation
Nov 04, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-39902
MEDIUM
GitLab 13.4-14.2.6 - Incorrect Authorization in Incident Severity Modification
Nov 04, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22263
MEDIUM
GitLab 13.0-14.0.8, 14.1-14.1.3, 14.2-14.2.1 - Privilege Escalation via Project Token Abuse
Oct 11, 2021
CVSS 5.5
EPSS 0.00
CVE-2021-39880
MEDIUM
GitLab 11.9-13.12, 14.0-14.0.8, 14.1-14.1.3, 14.2-14.2.1 - Denial of Service via Apollo Upload Server Middleware
Oct 05, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-39891
MEDIUM
GitLab CE/EE >=8.0 - Info Disclosure
Oct 05, 2021
CVSS 5.9
EPSS 0.00
CVE-2021-39889
MEDIUM
GitLab 14.1.0-14.1.7 - Authorization Bypass via Protected Branch ID
Oct 05, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-39886
LOW
GitLab 10.6.0-14.1.7 - Unauthenticated Confidential Epic Reference Exposure via Issue Move
Oct 05, 2021
CVSS 2.6
EPSS 0.00
CVE-2021-39881
LOW
GitLab 7.7.0-14.1.7 - OAuth Scope Spoofing via Arbitrary Scope Names
Oct 05, 2021
CVSS 3.5
EPSS 0.00
CVE-2021-39870
MEDIUM
GitLab 11.11.0-14.1.7 - Unauthenticated Repository Import Bypass via Crafted API Call
Oct 05, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22264
MEDIUM
GitLab <14.0.9-14.1.4-14.2.2 - Info Disclosure
Oct 05, 2021
CVSS 6.8
EPSS 0.00
CVE-2021-22262
MEDIUM
GitLab 13.12-14.0.8, 14.1-14.1.3, 14.2-14.2.1 - Incorrect Authorization in Jira Connect Namespace Management
Oct 05, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-22261
HIGH
GitLab 13.9-14.0.8, 14.1-14.1.3, 14.2-14.2.1 - Stored Cross-Site Scripting via Jira Integration
Oct 05, 2021
CVSS 7.3
EPSS 0.00
CVE-2021-22258
MEDIUM
GitLab 8.9-14.0.8 - Unauthenticated Email Address Exposure via Project Import/Export
Oct 05, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22257
MEDIUM
GitLab <14.0.9-14.2.2 - Info Disclosure
Oct 05, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-39894
MEDIUM
GitLab 8.0.0-14.1.7 - Server-Side Request Forgery via Fogbugz Importer DNS Rebinding
Oct 05, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-39893
MEDIUM
GitLab 9.1.0-14.1.6 - Unauthenticated Denial of Service via File Parsing
Oct 05, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-39888
MEDIUM
GitLab EE <14.1.7, <14.2.5, <14.3.1 - Info Disclosure
Oct 05, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-39884
MEDIUM
GitLab 8.13.0-14.1.7 - Unauthenticated Private Group Name Disclosure
Oct 05, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-39882
MEDIUM
GitLab - Unauthenticated Cleartext Transmission of Sensitive Information via User ID Endpoints
Oct 05, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-39878
MEDIUM
GitLab 13.0-14.3.1 - Stored Cross-Site Scripting in Jira Integration
Oct 05, 2021
CVSS 5.8
EPSS 0.00