gitlab

1,383 tracked vulnerabilities.

CVE-2021-32823 LOW
bindata < 2.4.10 - Denial of Service via Slow Bit Class Creation
Jun 24, 2021
CVSS 3.7
EPSS 0.00
CVE-2021-22181 HIGH
GitLab 11.8.0-13.10.4 - Denial of Service via Recursive Pipeline Relationship
Jun 11, 2021
CVSS 7.7
EPSS 0.00
CVE-2021-22175 MEDIUM KEVNUCLEI
GitLab 10.5.0-13.6.6 - Unauthenticated Server-Side Request Forgery via Webhook Internal Network Requests
Jun 11, 2021
CVSS 6.8
EPSS 0.80
CVE-2021-22220 MEDIUM
GitLab 13.10-13.10.5 - Stored Cross-Site Scripting in Blob Viewer of Notebooks
Jun 08, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-22216 MEDIUM
GitLab < 13.10.5 - Denial of Service via Long Issue or Merge Request Description
Jun 08, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-22221 MEDIUM
GitLab 12.9.0-13.10.4, 13.11.0-13.11.4, 13.12.0-13.12.1 - Insufficient Session Expiration
Jun 08, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-22219 MEDIUM
GitLab 9.5.0-13.10.4 13.11.0-13.11.4 13.12.0-13.12.1 - Sensitive Information Exposure in Log Files
Jun 08, 2021
CVSS 4.4
EPSS 0.00
CVE-2021-22217 MEDIUM
GitLab < 13.10.5 - Denial of Service via Specially Crafted Issue or Merge Request
Jun 08, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-22213 HIGH
GitLab 7.10.0-13.10.4 - Cross-Site Leak via OAuth Flow
Jun 08, 2021
CVSS 8.8
EPSS 0.01
CVE-2021-22218 LOW
GitLab 12.8-13.10.4, 13.11-13.11.4, 13.12-13.12.1 - Improper Certificate Validation
Jun 08, 2021
CVSS 2.6
EPSS 0.00
CVE-2021-22215 HIGH
GitLab 13.11.0-13.11.4 - Information Disclosure via On-Call Rotation Data
Jun 08, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-22214 MEDIUM NUCLEI
GitLab 10.5-13.10.4 - Unauthenticated Server-Side Request Forgery via Webhook Internal Network Requests
Jun 08, 2021
CVSS 6.8
EPSS 0.94
CVE-2021-22210 MEDIUM
GitLab 13.2.0-13.9.7 - Allocation of Resources Without Limits or Throttling via API Branch Query
May 06, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-22209 HIGH
GitLab 13.8.0-13.9.6 - Incorrect Authorization via GraphQL Mutation
May 06, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-22208 MEDIUM
GitLab 13.5.0-13.9.7 - Unauthenticated Issue Timestamp Manipulation
May 06, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22206 MEDIUM
GitLab 11.6.0-13.9.6 - Cleartext Storage of Sensitive Information in Pull Mirror Credentials
May 06, 2021
CVSS 6.8
EPSS 0.00
CVE-2021-22211 LOW
GitLab 13.7.0-13.9.6 - Incorrect Authorization via Dependency Proxy
May 06, 2021
CVSS 3.1
EPSS 0.00
CVE-2021-22205 CRITICAL KEVNUCLEI
GitLab 11.9.0-13.8.7 - Unauthenticated Remote Code Execution via ExifTool Image Parsing
Apr 23, 2021
CVSS 10.0
EPSS 0.94
CVE-2021-22199 LOW
GitLab 12.9-13.8.6 - Stored Cross-Site Scripting via Scoped Labels
Apr 22, 2021
CVSS 3.5
EPSS 0.00
CVE-2021-22190 HIGH
GitLab 13.7.0-13.7.8 - Path Traversal via GitLab Workhorse
Apr 12, 2021
CVSS 8.5
EPSS 0.00
CVE-2021-22203 HIGH
GitLab CE/EE <13.8.7/<13.9.5/<13.10.1 - Info Disclosure
Apr 02, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-22202 LOW
GitLab < 13.10.0 - Cross-Site Request Forgery via System Hooks API
Apr 02, 2021
CVSS 2.4
EPSS 0.00
CVE-2021-22201 CRITICAL
GitLab CE/EE <13.9 - Info Disclosure
Apr 02, 2021
CVSS 9.6
EPSS 0.09
CVE-2021-22200 MEDIUM
GitLab CE/EE <12.6 - Info Disclosure
Apr 02, 2021
CVSS 5.9
EPSS 0.00
CVE-2021-22198 MEDIUM
GitLab CE/EE >=13.8 - Privilege Escalation
Apr 02, 2021
CVSS 4.3
EPSS 0.00