gitlab
1,383 tracked vulnerabilities.
CVE-2021-22197
LOW
GitLab 10.6.0-13.8.6 - Authenticated Denial of Service via Merge Request Infinite Loop
Apr 02, 2021
CVSS 3.5
EPSS 0.00
CVE-2021-22196
MEDIUM
GitLab 13.4.0-13.8.6 - Stored Cross-Site Scripting via Merge Request Branch Name
Apr 02, 2021
CVSS 6.3
EPSS 0.00
CVE-2021-22195
HIGH
GitLab VSCode Extension < 3.15.0 - Client-Side Code Execution via Uncontrolled Search Path Element
Apr 01, 2021
CVSS 8.6
EPSS 0.00
CVE-2021-22177
MEDIUM
GitLab 12.6.0-13.6.6 - Denial of Service via gitlab-shell Command
Apr 01, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22194
MEDIUM
GitLab - Cleartext Storage of Sensitive Information in Redis
Mar 26, 2021
CVSS 5.7
EPSS 0.00
CVE-2021-22184
MEDIUM
GitLab 12.8.0-13.6.5 - Sensitive Information Disclosure in Server Logs
Mar 26, 2021
CVSS 6.2
EPSS 0.00
CVE-2021-22180
MEDIUM
GitLab 13.4-13.6.7 - Unauthenticated Direct Request Access to Analytic Pages
Mar 26, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22172
MEDIUM
GitLab 12.8.0-13.6.5 - Unauthenticated Exposure of Sensitive Tag Data via Releases Page
Mar 26, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22169
MEDIUM
GitLab 13.4.0-13.5.5 - Internal IP Address Exposure via Error Message
Mar 24, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22193
LOW
GitLab 7.1.0-13.6.5 - Information Disclosure via Private Project Name Validation
Mar 24, 2021
CVSS 3.5
EPSS 0.00
CVE-2021-22192
CRITICAL
GitLab CE/EE <13.2 - Authenticated RCE
Mar 24, 2021
CVSS 9.9
EPSS 0.81
CVE-2021-22186
MEDIUM
GitLab 9.4.0-13.7.7 - Incorrect Authorization in Group CI/CD Variables
Mar 24, 2021
CVSS 4.9
EPSS 0.00
CVE-2021-22185
MEDIUM
GitLab 13.8.0-13.8.4 - Stored Cross-Site Scripting in Wikis via Crafted Commit
Mar 24, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-22179
MEDIUM
GitLab 12.2.0-13.6.5 - Server-Side Request Forgery via Outbound Requests
Mar 24, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-22178
MEDIUM
GitLab 13.2.0-13.6.6 - Server-Side Request Forgery via Prometheus Integration
Mar 24, 2021
CVSS 5.0
EPSS 0.00
CVE-2021-22176
MEDIUM
GitLab 3.0.1-13.6.7 - Incorrect Authorization for Demoted Project Members
Mar 24, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22189
MEDIUM
GitLab < 13.6.7 - Improper Certificate Validation for Fortinet OTP
Mar 04, 2021
CVSS 5.9
EPSS 0.00
CVE-2021-22183
MEDIUM
GitLab 11.8-13.6.5 - Stored Cross-Site Scripting in Epics Page
Mar 04, 2021
CVSS 4.1
EPSS 0.00
CVE-2021-22188
MEDIUM
GitLab 13.0.0-13.6.6 - Unauthenticated Confidential Issue Title Exposure via Branch Logs
Mar 03, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-22182
LOW
GitLab 13.7.0-13.7.5 - Stored Cross-Site Scripting in Merge Request
Mar 03, 2021
CVSS 3.5
EPSS 0.00
CVE-2021-22187
MEDIUM
GitLab < 13.6.7 - Uncontrolled Resource Consumption via Deleted Project Job Persistence
Mar 02, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22171
HIGH
GitLab 11.5.0-13.5.5 - API Token Theft via Malicious Link
Jan 15, 2021
CVSS 7.3
EPSS 0.00
CVE-2021-22168
MEDIUM
GitLab 12.8.0-13.5.5 - Regular Expression Denial of Service in NuGet API
Jan 15, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22167
MEDIUM
GitLab 12.1.0-13.5.5 - Unauthenticated Temporary Private Repository Access via Incorrect Headers
Jan 15, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-22166
MEDIUM
GitLab 13.7.0-13.7.1 - Denial of Service via Malformed HTTP Method
Jan 15, 2021
CVSS 5.3
EPSS 0.00