Debian Gitlab vulnerabilities
1,325 known vulnerabilities affecting debian/gitlab.
Total CVEs
1,325
CISA KEV
4
actively exploited
Public exploits
22
Exploited in wild
2
Severity breakdown
CRITICAL43HIGH196MEDIUM630LOW456
Vulnerabilities
Page 66 of 67
CVE-2017-0921HIGHCVSS 8.1fixed in gitlab 10.7.7+dfsg-2 (sid)2017
CVE-2017-0921 [HIGH] CVE-2017-0921: gitlab - GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are v...
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.
Scope: local
sid: resolved (fixed in 10.7.7+dfsg-2)
debian
CVE-2017-0914HIGHCVSS 7.5fixed in gitlab 10.5.5+dfsg-1 (sid)2017
CVE-2017-0914 [HIGH] CVE-2017-0914: gitlab - Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vuln...
Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.
Scope: local
sid: resolved (fixed in 10.5.5+dfsg-1)
debian
CVE-2017-0920MEDIUMCVSS 4.3fixed in gitlab 10.5.5+dfsg-1 (sid)2017
CVE-2017-0920 [MEDIUM] CVE-2017-0920: gitlab - GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are v...
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.
Scope: local
sid: resolved (fixed in 10.5.5+dfsg-1)
debian
CVE-2017-0927MEDIUMCVSS 6.5fixed in gitlab 10.5.5+dfsg-1 (sid)2017
CVE-2017-0927 [MEDIUM] CVE-2017-0927: gitlab - Gitlab Community Edition version 10.3 is vulnerable to an improper authorization...
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.
Scope: local
sid: resolved (fixed in 10.5.5+dfsg-1)
debian
CVE-2017-0882MEDIUMCVSS 6.3fixed in gitlab 8.13.11+dfsg-7 (sid)2017
CVE-2017-0882 [MEDIUM] CVE-2017-0882: gitlab - Multiple versions of GitLab expose sensitive user credentials when assigning a u...
Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.
Scope: local
sid: resolved (fixed in 8.13.11+dfsg-7)
debian
CVE-2017-0923MEDIUMCVSS 6.1fixed in gitlab 10.5.5+dfsg-1 (sid)2017
CVE-2017-0923 [MEDIUM] CVE-2017-0923: gitlab - Gitlab Community Edition version 9.1 is vulnerable to lack of input validation i...
Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting.
Scope: local
sid: resolved (fixed in 10.5.5+dfsg-1)
debian
CVE-2017-0924MEDIUMCVSS 6.1fixed in gitlab 10.5.5+dfsg-1 (sid)2017
CVE-2017-0924 [MEDIUM] CVE-2017-0924: gitlab - Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validatio...
Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in persistent cross site scripting.
Scope: local
sid: resolved (fixed in 10.5.5+dfsg-1)
debian
CVE-2017-0917MEDIUMCVSS 6.1fixed in gitlab 10.5.5+dfsg-1 (sid)2017
CVE-2017-0917 [MEDIUM] CVE-2017-0917: gitlab - Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validatio...
Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.
Scope: local
sid: resolved (fixed in 10.5.5+dfsg-1)
debian
CVE-2017-11438LOWCVSS 6.32017
CVE-2017-11438 [MEDIUM] CVE-2017-11438: gitlab - GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, ...
GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group to add themselves to any project that is inside a subgroup.
Scope: local
sid: resolved
debian
CVE-2017-12426LOWCVSS 8.8fixed in gitlab 9.5.4+dfsg-7 (sid)2017
CVE-2017-12426 [HIGH] CVE-2017-12426: gitlab - GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x b...
GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.
Scope: local
sid: resolved (fixed in 9.5.4+dfsg-7)
debian
CVE-2017-17716LOWCVSS 5.92017
CVE-2017-17716 [MEDIUM] CVE-2017-17716: gitlab - GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, bu...
GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release announcement. This issue occurred because code was not merged. This is related to use of the omniauth-ldap library and the gitlab_omniauth-ldap gem.
Scope: local
sid: resolved
debian
CVE-2017-8778LOWCVSS 6.12017
CVE-2017-8778 [MEDIUM] CVE-2017-8778: gitlab - GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via...
GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG document.
Scope: local
sid: resolved
debian
CVE-2017-11437LOWCVSS 6.52017
CVE-2017-11437 [MEDIUM] CVE-2017-11437: gitlab - GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 al...
GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read repositories belonging to other users.
Scope: local
sid: resolved
debian
CVE-2016-4340HIGHCVSS 8.8PoCfixed in gitlab 8.8.2+dfsg-1 (sid)2016
CVE-2016-4340 [HIGH] CVE-2016-4340: gitlab - The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5....
The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.
Scope: local
sid: resolved (fixed in 8.8.2+dfsg-1)
debian
CVE-2016-9469HIGHCVSS 8.2fixed in gitlab 8.13.6+dfsg2-2 (sid)2016
CVE-2016-9469 [HIGH] CVE-2016-9469: gitlab - Multiple versions of GitLab expose a dangerous method to any authenticated user ...
Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be exploited by an unauthenticated user. A fix was included in versions 8.14.3, 8.13.8, and 8.12.11, which were released
debian
CVE-2016-9086MEDIUMCVSS 6.5fixed in gitlab 8.13.3+dfsg1-2 (sid)2016
CVE-2016-9086 [MEDIUM] CVE-2016-9086: gitlab - GitLab versions 8.9.x and above contain a critical security flaw in the "import/...
GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files (tar). All GitLab versions prior to 8.13.0 restricted this feature to administrators only. Starting with version 8.13.0 this feature was mad
debian
CVE-2014-8540LOWCVSS 6.52014
CVE-2014-8540 [MEDIUM] CVE-2014-8540: gitlab - The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated gu...
The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.
Scope: local
sid: resolved
debian
CVE-2013-4581LOWCVSS 6.82013
CVE-2013-4581 [MEDIUM] CVE-2013-4581: gitlab - GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition befo...
GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.
Scope: local
sid: resolved
debian
CVE-2013-4490LOWCVSS 6.5PoC2013
CVE-2013-4490 [MEDIUM] CVE-2013-4490: gitlab - The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as...
The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.
Scope: local
sid: resolved
debian
CVE-2013-4580LOWCVSS 6.82013
CVE-2013-4580 [MEDIUM] CVE-2013-4580: gitlab - GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition befo...
GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.
Scope: local
sid: resolved
debian