Gitlab Ce vulnerabilities

572 known vulnerabilities affecting gitlab/gitlab_ce.

Total CVEs
572
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL18HIGH128MEDIUM342LOW84

Vulnerabilities

Page 12 of 29
CVE-2024-7091MEDIUMCVSS 4.12024-07-24
CVE-2024-7091 [MEDIUM] CWE-200 CVE-2024-7091: An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting fr CVE-2024-7091: An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.
gitlab
CVE-2024-7060LOWCVSS 2.62024-07-24
CVE-2024-7060 [LOW] CWE-200 CVE-2024-7060: An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1. CVE-2024-7060: An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.
gitlab
CVE-2024-0231LOWCVSS 2.72024-07-24
CVE-2024-0231 [LOW] CWE-99 CVE-2024-0231: A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker CVE-2024-0231: A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits.
gitlab
CVE-2024-6595LOWCVSS 3.02024-07-17
CVE-2024-6595 [LOW] CWE-451 CVE-2024-6595: An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting f CVE-2024-6595: An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.
gitlab
CVE-2024-6385CRITICALCVSS 9.62024-07-11
CVE-2024-6385 [CRITICAL] CWE-284 CVE-2024-6385: An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting f CVE-2024-6385: An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.
gitlab
CVE-2024-5257MEDIUMCVSS 4.92024-07-11
CVE-2024-5257 [MEDIUM] CWE-284 CVE-2024-5257: An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user CVE-2024-5257: An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.
gitlab
CVE-2024-2880LOWCVSS 2.72024-07-11
CVE-2024-2880 [LOW] CWE-284 CVE-2024-2880: An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting f CVE-2024-2880: An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members.
gitlab
CVE-2024-5470LOWCVSS 3.82024-07-11
CVE-2024-5470 [LOW] CWE-284 CVE-2024-5470: An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user wit CVE-2024-5470: An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.
gitlab
CVE-2024-2177MEDIUMCVSS 6.82024-07-09
CVE-2024-2177 [MEDIUM] CWE-1021 CVE-2024-2177: A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prio CVE-2024-2177: A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.
gitlab
CVE-2024-5655CRITICALCVSS 9.62024-06-27
CVE-2024-5655 [CRITICAL] CWE-284 CVE-2024-5655: An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting f CVE-2024-5655: An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.
gitlab
CVE-2024-4901HIGHCVSS 8.72024-06-27
CVE-2024-4901 [HIGH] CWE-79 CVE-2024-4901: An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting f CVE-2024-4901: An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.
gitlab
CVE-2024-5430MEDIUMCVSS 6.82024-06-27
CVE-2024-5430 [MEDIUM] CWE-284 CVE-2024-5430: An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting CVE-2024-5430: An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.
gitlab
CVE-2024-1493MEDIUMCVSS 6.52024-06-27
CVE-2024-1493 [MEDIUM] CWE-1333 CVE-2024-1493: An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting fr CVE-2024-1493: An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, with the processing logic for generating link in dependency files can lead to a regular expression DoS attack on
gitlab
CVE-2024-4557MEDIUMCVSS 6.52024-06-27
CVE-2024-4557 [MEDIUM] CWE-400 CVE-2024-4557: Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting fr CVE-2024-4557: Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline
gitlab
CVE-2024-2191MEDIUMCVSS 5.32024-06-27
CVE-2024-2191 [MEDIUM] CWE-284 CVE-2024-2191: An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting f CVE-2024-2191: An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.
gitlab
CVE-2024-3959MEDIUMCVSS 6.52024-06-27
CVE-2024-3959 [MEDIUM] CWE-285 CVE-2024-3959: An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting f CVE-2024-3959: An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.
gitlab
CVE-2024-1816MEDIUMCVSS 5.32024-06-27
CVE-2024-1816 [MEDIUM] CWE-400 CVE-2024-1816: An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting f CVE-2024-1816: An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file.
gitlab
CVE-2024-4011LOWCVSS 3.12024-06-27
CVE-2024-4011 [LOW] CWE-863 CVE-2024-4011: An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting f CVE-2024-4011: An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.
gitlab
CVE-2024-5469LOWCVSS 3.12024-06-14
CVE-2024-5469 [LOW] CWE-754 CVE-2024-5469: DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via craft CVE-2024-5469: DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests.
gitlab
CVE-2024-1495MEDIUMCVSS 6.52024-06-12
CVE-2024-1495 [MEDIUM] CWE-1333 CVE-2024-1495: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.1 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and sta CVE-2024-1495: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.1 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. It was possible for an attacker to cause a denial of service using maliciously crafted file.
gitlab