gitlab

1,383 tracked vulnerabilities.

CVE-2021-22197 LOW
GitLab 10.6.0-13.8.6 - Authenticated Denial of Service via Merge Request Infinite Loop
Apr 02, 2021
CVSS 3.5
EPSS 0.00
CVE-2021-22196 MEDIUM
GitLab 13.4.0-13.8.6 - Stored Cross-Site Scripting via Merge Request Branch Name
Apr 02, 2021
CVSS 6.3
EPSS 0.00
CVE-2021-22195 HIGH
GitLab VSCode Extension < 3.15.0 - Client-Side Code Execution via Uncontrolled Search Path Element
Apr 01, 2021
CVSS 8.6
EPSS 0.00
CVE-2021-22177 MEDIUM
GitLab 12.6.0-13.6.6 - Denial of Service via gitlab-shell Command
Apr 01, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22194 MEDIUM
GitLab - Cleartext Storage of Sensitive Information in Redis
Mar 26, 2021
CVSS 5.7
EPSS 0.00
CVE-2021-22184 MEDIUM
GitLab 12.8.0-13.6.5 - Sensitive Information Disclosure in Server Logs
Mar 26, 2021
CVSS 6.2
EPSS 0.00
CVE-2021-22180 MEDIUM
GitLab 13.4-13.6.7 - Unauthenticated Direct Request Access to Analytic Pages
Mar 26, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22172 MEDIUM
GitLab 12.8.0-13.6.5 - Unauthenticated Exposure of Sensitive Tag Data via Releases Page
Mar 26, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22169 MEDIUM
GitLab 13.4.0-13.5.5 - Internal IP Address Exposure via Error Message
Mar 24, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22193 LOW
GitLab 7.1.0-13.6.5 - Information Disclosure via Private Project Name Validation
Mar 24, 2021
CVSS 3.5
EPSS 0.00
CVE-2021-22192 CRITICAL
GitLab CE/EE <13.2 - Authenticated RCE
Mar 24, 2021
CVSS 9.9
EPSS 0.81
CVE-2021-22186 MEDIUM
GitLab 9.4.0-13.7.7 - Incorrect Authorization in Group CI/CD Variables
Mar 24, 2021
CVSS 4.9
EPSS 0.00
CVE-2021-22185 MEDIUM
GitLab 13.8.0-13.8.4 - Stored Cross-Site Scripting in Wikis via Crafted Commit
Mar 24, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-22179 MEDIUM
GitLab 12.2.0-13.6.5 - Server-Side Request Forgery via Outbound Requests
Mar 24, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-22178 MEDIUM
GitLab 13.2.0-13.6.6 - Server-Side Request Forgery via Prometheus Integration
Mar 24, 2021
CVSS 5.0
EPSS 0.00
CVE-2021-22176 MEDIUM
GitLab 3.0.1-13.6.7 - Incorrect Authorization for Demoted Project Members
Mar 24, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22189 MEDIUM
GitLab < 13.6.7 - Improper Certificate Validation for Fortinet OTP
Mar 04, 2021
CVSS 5.9
EPSS 0.00
CVE-2021-22183 MEDIUM
GitLab 11.8-13.6.5 - Stored Cross-Site Scripting in Epics Page
Mar 04, 2021
CVSS 4.1
EPSS 0.00
CVE-2021-22188 MEDIUM
GitLab 13.0.0-13.6.6 - Unauthenticated Confidential Issue Title Exposure via Branch Logs
Mar 03, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-22182 LOW
GitLab 13.7.0-13.7.5 - Stored Cross-Site Scripting in Merge Request
Mar 03, 2021
CVSS 3.5
EPSS 0.00
CVE-2021-22187 MEDIUM
GitLab < 13.6.7 - Uncontrolled Resource Consumption via Deleted Project Job Persistence
Mar 02, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22171 HIGH
GitLab 11.5.0-13.5.5 - API Token Theft via Malicious Link
Jan 15, 2021
CVSS 7.3
EPSS 0.00
CVE-2021-22168 MEDIUM
GitLab 12.8.0-13.5.5 - Regular Expression Denial of Service in NuGet API
Jan 15, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22167 MEDIUM
GitLab 12.1.0-13.5.5 - Unauthenticated Temporary Private Repository Access via Incorrect Headers
Jan 15, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-22166 MEDIUM
GitLab 13.7.0-13.7.1 - Denial of Service via Malformed HTTP Method
Jan 15, 2021
CVSS 5.3
EPSS 0.00