Gitlab Ce vulnerabilities
572 known vulnerabilities affecting gitlab/gitlab_ce.
Total CVEs
572
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL18HIGH128MEDIUM342LOW84
Vulnerabilities
Page 15 of 29
CVE-2023-4008MEDIUMCVSS 5.32023-08-03
CVE-2023-4008 [MEDIUM] CWE-708 CVE-2023-4008: An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, a
CVE-2023-4008: An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages with unique domain URLs if the random string added
gitlab
CVE-2023-3364HIGHCVSS 7.52023-08-02
CVE-2023-3364 [HIGH] CWE-1333 CVE-2023-3364: An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14 before 16.0.8, all versions starting from 16.1 before 16.1.3, a
CVE-2023-3364: An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use Au
gitlab
CVE-2023-3994HIGHCVSS 7.52023-08-02
CVE-2023-3994 [HIGH] CWE-1333 CVE-2023-3994: An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, al
CVE-2023-3994: An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use Pro
gitlab
CVE-2023-3900MEDIUMCVSS 4.32023-08-02
CVE-2023-3900 [MEDIUM] CWE-1287 CVE-2023-3900: An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A
CVE-2023-3900: An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.
gitlab
CVE-2023-3500MEDIUMCVSS 4.82023-08-02
CVE-2023-3500 [MEDIUM] CWE-79 CVE-2023-3500: An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, a
CVE-2023-3500: An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attack
gitlab
CVE-2023-2022MEDIUMCVSS 4.32023-08-02
CVE-2023-2022 [MEDIUM] CWE-262 CVE-2023-2022: An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all version
CVE-2023-2022: An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they d
gitlab
CVE-2023-3424HIGHCVSS 7.52023-07-13
CVE-2023-3424 [HIGH] CWE-1333 CVE-2023-3424: An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6,
CVE-2023-3424: An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service was possible via sending crafted payloads to the pre
gitlab
CVE-2023-2190MEDIUMCVSS 6.52023-07-13
CVE-2023-2190 [MEDIUM] CWE-639 CVE-2023-2190: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6
CVE-2023-2190: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. It may be possible for users to view new commits to private projects in a fork created wh
gitlab
CVE-2023-2200MEDIUMCVSS 4.12023-07-13
CVE-2023-2200 [MEDIUM] CWE-116 CVE-2023-2200: An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6,
CVE-2023-2200: An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML in an email address field.
gitlab
CVE-2023-3362MEDIUMCVSS 5.32023-07-13
CVE-2023-3362 [MEDIUM] CWE-209 CVE-2023-3362: An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to
CVE-2023-3362: An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.
gitlab
CVE-2023-2620MEDIUMCVSS 5.52023-07-13
CVE-2023-2620 [MEDIUM] CWE-201 CVE-2023-2620: An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all
CVE-2023-2620: An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked por
gitlab
CVE-2023-2576MEDIUMCVSS 4.32023-07-13
CVE-2023-2576 [MEDIUM] CWE-863 CVE-2023-2576: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6,
CVE-2023-2576: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CODEOWNERS rules and merge to a protected branch.
gitlab
CVE-2023-3444MEDIUMCVSS 5.72023-07-13
CVE-2023-3444 [MEDIUM] CWE-863 CVE-2023-3444: An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6,
CVE-2023-3444: An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches.
gitlab
CVE-2023-3363LOWCVSS 3.92023-07-13
CVE-2023-3363 [LOW] CWE-532 CVE-2023-3363: An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versio
CVE-2023-3363: An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`.
gitlab
CVE-2023-1936LOWCVSS 3.52023-07-11
CVE-2023-1936 [LOW] CWE-359 CVE-2023-1936: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6,
CVE-2023-1936: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a service desk issue
gitlab
CVE-2023-2199HIGHCVSS 7.52023-06-07
CVE-2023-2199 [HIGH] CWE-1333 CVE-2023-2199: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7
CVE-2023-2199: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the pr
gitlab
CVE-2023-2442HIGHCVSS 8.72023-06-07
CVE-2023-2442 [HIGH] CWE-79 CVE-2023-2442: An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2.
CVE-2023-2442: An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behal
gitlab
CVE-2023-2198HIGHCVSS 7.52023-06-07
CVE-2023-2198 [HIGH] CWE-1333 CVE-2023-2198: An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7,
CVE-2023-2198: An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the pre
gitlab
CVE-2023-2485MEDIUMCVSS 4.42023-06-07
CVE-2023-2485 [MEDIUM] CWE-266 CVE-2023-2485: An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7
CVE-2023-2485: An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if
gitlab
CVE-2023-2015MEDIUMCVSS 4.42023-06-07
CVE-2023-2015 [MEDIUM] CWE-79 CVE-2023-2015: An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.7
CVE-2023-2015: An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A reflected XSS was possible when creating new abuse reports which allows attackers to per
gitlab