Debian Gitlab vulnerabilities

1,325 known vulnerabilities affecting debian/gitlab.

Total CVEs
1,325
CISA KEV
4
actively exploited
Public exploits
22
Exploited in wild
2
Severity breakdown
CRITICAL43HIGH196MEDIUM630LOW456

Vulnerabilities

Page 30 of 67
CVE-2022-3478MEDIUMCVSS 4.3fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-3478 [MEDIUM] CVE-2022-3478: gitlab - An issue has been discovered in GitLab affecting all versions starting from 12.8... An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible to trigger a DoS attack by uploading a malicious nuget package. Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2022-3759MEDIUMCVSS 4.3fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-3759 [MEDIUM] CVE-2022-3759: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions starting fro... An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. An attacker may upload a crafted CI job artifact zip file in a project that uses dynamic child pipelines and make a sidekiq job allocate a lot of memory. In GitLab instances
debian
CVE-2022-0136MEDIUMCVSS 5.4fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-0136 [MEDIUM] CVE-2022-0136: gitlab - A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4... A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature. Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2022-0549MEDIUMCVSS 6.5fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-0549 [MEDIUM] CVE-2022-0549: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.... An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under certain conditions, GitLab REST API may allow unprivileged users to add other users to groups even if that is not possible to do through the Web UI. Scope: local sid: resolved (fixed in
debian
CVE-2022-0125MEDIUMCVSS 4.3fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-0125 [MEDIUM] CVE-2022-0125: gitlab - An issue has been discovered in GitLab affecting all versions starting from 12.0... An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project. Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2022-1944MEDIUMCVSS 5.4fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-1944 [MEDIUM] CVE-2022-1944: gitlab - When the feature is configured, improper authorization in the Interactive Web Te... When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers' running jobs Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2022-3030MEDIUMCVSS 4.3fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-3030 [MEDIUM] CVE-2022-3030: gitlab - An improper access control issue in GitLab CE/EE affecting all versions starting... An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users. Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2022-1124MEDIUMCVSS 4.3fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-1124 [MEDIUM] CVE-2022-1124: gitlab - An improper authorization issue has been discovered in GitLab CE/EE affecting al... An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2022-2539MEDIUMCVSS 5.3fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-2539 [MEDIUM] CVE-2022-2539: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions starting fro... An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.6 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1, allowed a project member to filter issues by contact and organization. Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2022-3639MEDIUMCVSS 4.3fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-3639 [MEDIUM] CVE-2022-3639: gitlab - A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versi... A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage. Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2022-1406MEDIUMCVSS 6.5fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-1406 [MEDIUM] CVE-2022-1406: gitlab - Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior... Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2022-0151MEDIUMCVSS 6.5fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-0151 [MEDIUM] CVE-2022-0151: gitlab - An issue has been discovered in GitLab affecting all versions starting from 12.1... An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could result in a Denial of Service under specific conditions. Scope: local sid: resolved (fixed
debian
CVE-2022-2250MEDIUMCVSS 4.7fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-2250 [MEDIUM] CVE-2022-2250: gitlab - An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 ... An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL. Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2022-3613MEDIUMCVSS 5.8fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-3613 [MEDIUM] CVE-2022-3613: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.... An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of Service. Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2022-3482MEDIUMCVSS 5.3fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-3482 [MEDIUM] CVE-2022-3482: gitlab - An improper access control issue in GitLab CE/EE affecting all versions from 11.... An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allowed an unauthorized user to see release names even when releases we set to be restricted to project members only Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2022-1099MEDIUMCVSS 4.3fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-1099 [MEDIUM] CVE-2022-1099: gitlab - Adding a very large number of tags to a runner in GitLab CE/EE affecting all ver... Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2022-1193MEDIUMCVSS 4.3fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-1193 [MEDIUM] CVE-2022-1193: gitlab - Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prio... Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2022-2244MEDIUMCVSS 4.3fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-2244 [MEDIUM] CVE-2022-2244: gitlab - An improper authorization vulnerability in GitLab EE/CE affecting all versions f... An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows project memebers with reporter role to manage issues in project's error tracking feature. Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2022-2417MEDIUMCVSS 6.2fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-2417 [MEDIUM] CVE-2022-2417: gitlab - Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior ... Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could be abused in supply chain attacks where a victim pinned to a specific Git commit of the pro
debian
CVE-2022-3330MEDIUMCVSS 4.3fixed in gitlab 15.10.8+ds1-2 (sid)2022
CVE-2022-3330 [MEDIUM] CVE-2022-3330: gitlab - It was possible for a guest user to read a todo targeting an inaccessible note i... It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1. Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian