gitlab

1,383 tracked vulnerabilities.

CVE-2021-39898 LOW
GitLab 10.6.0-14.1.6 - Exposure of Sensitive Information via Project Export
Nov 05, 2021
CVSS 3.7
EPSS 0.00
CVE-2021-39897 LOW
GitLab CE/EE >=10.5 - Info Disclosure
Nov 05, 2021
CVSS 2.6
EPSS 0.00
CVE-2021-39895 MEDIUM
GitLab 8.0.0-14.1.7 - Information Disclosure via Imported Pipeline Schedules
Nov 05, 2021
CVSS 6.0
EPSS 0.00
CVE-2021-22260 HIGH
GitLab 13.7-14.0.8, 14.1-14.1.3, 14.2-14.2.1 - Stored Cross-Site Scripting in DataDog Integration
Nov 05, 2021
CVSS 7.7
EPSS 0.00
CVE-2021-39914 LOW
GitLab 8.13-14.2.5 14.3.0-14.3.3 14.4.0 - Regular Expression Denial of Service via Username Provisioning
Nov 04, 2021
CVSS 3.1
EPSS 0.00
CVE-2021-39903 MEDIUM
GitLab CE/EE <13.0 - Privilege Escalation
Nov 04, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-39902 MEDIUM
GitLab 13.4-14.2.6 - Incorrect Authorization in Incident Severity Modification
Nov 04, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22263 MEDIUM
GitLab 13.0-14.0.8, 14.1-14.1.3, 14.2-14.2.1 - Privilege Escalation via Project Token Abuse
Oct 11, 2021
CVSS 5.5
EPSS 0.00
CVE-2021-39880 MEDIUM
GitLab 11.9-13.12, 14.0-14.0.8, 14.1-14.1.3, 14.2-14.2.1 - Denial of Service via Apollo Upload Server Middleware
Oct 05, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-39891 MEDIUM
GitLab CE/EE >=8.0 - Info Disclosure
Oct 05, 2021
CVSS 5.9
EPSS 0.00
CVE-2021-39889 MEDIUM
GitLab 14.1.0-14.1.7 - Authorization Bypass via Protected Branch ID
Oct 05, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-39886 LOW
GitLab 10.6.0-14.1.7 - Unauthenticated Confidential Epic Reference Exposure via Issue Move
Oct 05, 2021
CVSS 2.6
EPSS 0.00
CVE-2021-39881 LOW
GitLab 7.7.0-14.1.7 - OAuth Scope Spoofing via Arbitrary Scope Names
Oct 05, 2021
CVSS 3.5
EPSS 0.00
CVE-2021-39870 MEDIUM
GitLab 11.11.0-14.1.7 - Unauthenticated Repository Import Bypass via Crafted API Call
Oct 05, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22264 MEDIUM
GitLab <14.0.9-14.1.4-14.2.2 - Info Disclosure
Oct 05, 2021
CVSS 6.8
EPSS 0.00
CVE-2021-22262 MEDIUM
GitLab 13.12-14.0.8, 14.1-14.1.3, 14.2-14.2.1 - Incorrect Authorization in Jira Connect Namespace Management
Oct 05, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-22261 HIGH
GitLab 13.9-14.0.8, 14.1-14.1.3, 14.2-14.2.1 - Stored Cross-Site Scripting via Jira Integration
Oct 05, 2021
CVSS 7.3
EPSS 0.00
CVE-2021-22258 MEDIUM
GitLab 8.9-14.0.8 - Unauthenticated Email Address Exposure via Project Import/Export
Oct 05, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22257 MEDIUM
GitLab <14.0.9-14.2.2 - Info Disclosure
Oct 05, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-39894 MEDIUM
GitLab 8.0.0-14.1.7 - Server-Side Request Forgery via Fogbugz Importer DNS Rebinding
Oct 05, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-39893 MEDIUM
GitLab 9.1.0-14.1.6 - Unauthenticated Denial of Service via File Parsing
Oct 05, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-39888 MEDIUM
GitLab EE <14.1.7, <14.2.5, <14.3.1 - Info Disclosure
Oct 05, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-39884 MEDIUM
GitLab 8.13.0-14.1.7 - Unauthenticated Private Group Name Disclosure
Oct 05, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-39882 MEDIUM
GitLab - Unauthenticated Cleartext Transmission of Sensitive Information via User ID Endpoints
Oct 05, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-39878 MEDIUM
GitLab 13.0-14.3.1 - Stored Cross-Site Scripting in Jira Integration
Oct 05, 2021
CVSS 5.8
EPSS 0.00