cbcvebase.

Debian Gitlab vulnerabilities

863 known vulnerabilities affecting debian/gitlab.

Total CVEs
863
CISA KEV
4
actively exploited
Public exploits
18
Exploited in wild
7
Severity breakdown
CRITICAL43HIGH158MEDIUM552LOW110

Vulnerabilities

Page 40 of 44
CVE-2021-39931P4LOWCVSS 3.1fixed in gitlab 15.10.8+ds1-2 (sid)2021
CVE-2021-39931 [LOW] CVE-2021-39931: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions starting fro... An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error. Scope: local sid: resolved (fixed in 15.10.8
debian
CVE-2020-13344P4MEDIUMCVSS 5.7fixed in gitlab 13.2.10-1 (sid)2020
CVE-2020-13344 [MEDIUM] CVE-2020-13344: gitlab - An issue has been discovered in GitLab affecting all versions prior to 13.2.10, ... An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are stored in plain-text in Redis which allows attacker with Redis access to authenticate as any user that has a session stored in Redis Scope: local sid: resolved (fixed in 13.2.10-1)
debian
CVE-2021-22211P4LOWCVSS 3.1fixed in gitlab 15.10.8+ds1-2 (sid)2021
CVE-2021-22211 [LOW] CVE-2021-22211: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions starting fro... An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling. Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2024-5469P4LOWCVSS 3.1fixed in gitlab 17.3.5-2 (sid)2024
CVE-2024-5469 [LOW] CVE-2024-5469: gitlab - DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 ... DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests. Scope: local sid: resolved (fixed in 17.3.5-2)
debian
CVE-2024-6685P4LOWCVSS 3.1fixed in gitlab 17.3.5-2 (sid)2024
CVE-2024-6685 [LOW] CVE-2024-6685: gitlab - An issue was discovered in GitLab CE/EE affecting all versions starting from 16.... An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2, where group runners information was disclosed to unauthorised group members. Scope: local sid: resolved (fixed in 17.3.5-2)
debian
CVE-2021-39910P4LOWCVSS 2.6fixed in gitlab 15.10.8+ds1-2 (sid)2021
CVE-2021-39910 [LOW] CVE-2021-39910: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions starting fro... An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature. Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2023-2013P4LOWCVSS 2.6fixed in gitlab 15.10.8+ds1-2 (sid)2023
CVE-2023-2013 [LOW] CVE-2023-2013: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions starting fro... An issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning n
debian
CVE-2021-22239P4MEDIUMCVSS 5.0fixed in gitlab 15.10.8+ds1-2 (sid)2021
CVE-2021-22239 [MEDIUM] CVE-2021-22239: gitlab - An unauthorized user was able to insert metadata when creating new issue on GitL... An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later. Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2021-39886P4LOWCVSS 2.6fixed in gitlab 15.10.8+ds1-2 (sid)2021
CVE-2021-39886 [LOW] CVE-2021-39886: gitlab - Permissions rules were not applied while issues were moved between projects of t... Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references. Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2024-8974P4LOWCVSS 2.6fixed in gitlab 17.3.5-3 (sid)2024
CVE-2024-8974 [LOW] CVE-2024-8974: gitlab - Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to... Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project." Scope: local sid: resolved (fixed in 17.3.5-3)
debian
CVE-2021-22187P4MEDIUMCVSS 4.3fixed in gitlab 13.2.3-2 (sid)2021
CVE-2021-22187 [MEDIUM] CVE-2021-22187: gitlab - An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE be... An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted. Scope: local sid: resolved (fixed in 13.2.3-2)
debian
CVE-2021-39905P4MEDIUMCVSS 4.3fixed in gitlab 15.10.8+ds1-2 (sid)2021
CVE-2021-39905 [MEDIUM] CVE-2021-39905: gitlab - An information disclosure vulnerability in the GitLab CE/EE API since version 8.... An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with Scope: local sid: resolved (fixed in 15.10.8+ds1-2)
debian
CVE-2019-5466P4MEDIUMCVSS 4.3fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-5466 [MEDIUM] CVE-2019-5466: gitlab - An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge req... An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2019-6794P4MEDIUMCVSS 4.3fixed in gitlab 11.5.10+dfsg-1 (sid)2019
CVE-2019-6794 [MEDIUM] CVE-2019-6794: gitlab - An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8... An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 5 of 6). A project guest user can view the last commit status of the default branch. Scope: local sid: resolved (fixed in 11.5.10+dfsg-1)
debian
CVE-2020-10975P4MEDIUMCVSS 4.3fixed in gitlab 13.2.3-2 (sid)2020
CVE-2020-10975 [MEDIUM] CVE-2020-10975: gitlab - GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments on vulnerabilities to... GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments on vulnerabilities to unauthorized users on the vulnerability feedback page. Scope: local sid: resolved (fixed in 13.2.3-2)
debian
CVE-2020-10979P4MEDIUMCVSS 4.3fixed in gitlab 13.2.3-2 (sid)2020
CVE-2020-10979 [MEDIUM] CVE-2020-10979: gitlab - GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines met... GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users. Scope: local sid: resolved (fixed in 13.2.3-2)
debian
CVE-2019-12432P4MEDIUMCVSS 4.3fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-12432 [MEDIUM] CVE-2019-12432: gitlab - An issue was discovered in GitLab Community and Enterprise Edition 8.13 through ... An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2020-10981P4MEDIUMCVSS 4.3fixed in gitlab 13.2.3-2 (sid)2020
CVE-2020-10981 [MEDIUM] CVE-2020-10981: gitlab - GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeli... GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeline trigger descriptions within the same project. Scope: local sid: resolved (fixed in 13.2.3-2)
debian
CVE-2019-18446P4MEDIUMCVSS 4.3fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-18446 [MEDIUM] CVE-2019-18446: gitlab - An issue was discovered in GitLab Community and Enterprise Edition 8.15 through ... An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue 1 of 2). Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2023-3246P4MEDIUMCVSS 4.3fixed in gitlab 16.4.4+ds2-2 (sid)2023
CVE-2023-3246 [MEDIUM] CVE-2023-3246: gitlab - An issue has been discovered in GitLab EE/CE affecting all versions starting bef... An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job processor. Scope: local sid: resolved (fixed in 16.4.4+ds2-2)
debian
Debian Gitlab vulnerabilities | cvebase