Gitlab Ce vulnerabilities

572 known vulnerabilities affecting gitlab/gitlab_ce.

Total CVEs
572
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL18HIGH128MEDIUM342LOW84

Vulnerabilities

Page 21 of 29
CVE-2022-1148MEDIUMCVSS 5.32022-04-04
CVE-2022-1148 [MEDIUM] CWE-565 CVE-2022-1148: Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 pri CVE-2022-1148: Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that toke
gitlab
CVE-2022-1105MEDIUMCVSS 4.32022-04-04
CVE-2022-1105 [MEDIUM] CVE-2022-1105: An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14 CVE-2022-1105: An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled
gitlab
CVE-2022-1185MEDIUMCVSS 6.52022-04-04
CVE-2022-1185 [MEDIUM] CWE-787 CVE-2022-1185: A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an at CVE-2022-1185: A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file
gitlab
CVE-2022-1189LOWCVSS 3.12022-04-04
CVE-2022-1189 [LOW] CVE-2022-1189: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions starting from 14.8 before 14.8.5, a CVE-2022-1189: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 that allowed for an unauthorised user to read the the approval rules of a private project.
gitlab
CVE-2022-1188LOWCVSS 3.72022-04-04
CVE-2022-1188 [LOW] CWE-918 CVE-2022-1188: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, a CVE-2022-1188: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.
gitlab
CVE-2022-0740LOWCVSS 3.12022-04-04
CVE-2022-0740 [LOW] CWE-863 CVE-2022-0740: Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7. CVE-2022-0740: Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from u
gitlab
CVE-2022-1111LOWCVSS 2.42022-04-04
CVE-2022-1111 [LOW] CVE-2022-1111: A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain c CVE-2022-1111: A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages
gitlab
CVE-2022-0741MEDIUMCVSS 5.82022-04-01
CVE-2022-0741 [MEDIUM] CWE-116 CVE-2022-0741: Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables via special CVE-2022-0741: Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables via specially crafted email addresses.
gitlab
CVE-2021-39908MEDIUMCVSS 6.52022-04-01
CVE-2021-39908 [MEDIUM] CWE-94 CVE-2021-39908: In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 CVE-2021-39908: In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or s
gitlab
CVE-2022-0425MEDIUMCVSS 5.42022-04-01
CVE-2022-0425 [MEDIUM] CWE-918 CVE-2022-0425: A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Ser CVE-2022-0425: A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.
gitlab
CVE-2022-0373MEDIUMCVSS 4.32022-04-01
CVE-2022-0373 [MEDIUM] CVE-2022-0373: Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service CVE-2022-0373: Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address
gitlab
CVE-2022-0390MEDIUMCVSS 4.32022-04-01
CVE-2022-0390 [MEDIUM] CWE-862 CVE-2022-0390: Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue CVE-2022-0390: Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.
gitlab
CVE-2022-0489LOWCVSS 3.52022-04-01
CVE-2022-0489 [LOW] CWE-400 CVE-2022-0489: An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature wi CVE-2022-0489: An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.
gitlab
CVE-2022-0735CRITICALCVSS 10.0PoC2022-03-28
CVE-2022-0735 [CRITICAL] CVE-2022-0735: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, CVE-2022-0735: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosur
gitlab
CVE-2022-0427HIGHCVSS 7.72022-03-28
CVE-2022-0427 [HIGH] CWE-352 CVE-2022-0427: Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrar CVE-2022-0427: Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover
gitlab
CVE-2021-39876MEDIUMCVSS 4.32022-03-28
CVE-2021-39876 [MEDIUM] CWE-863 CVE-2021-39876: In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups. CVE-2021-39876: In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.
gitlab
CVE-2022-0549MEDIUMCVSS 6.52022-03-28
CVE-2022-0549 [MEDIUM] CVE-2022-0549: An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions startin CVE-2022-0549: An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under certain conditions, GitLab REST API may allow unprivileged users to add other users to groups even if that is not
gitlab
CVE-2021-4191MEDIUMCVSS 5.3PoC2022-03-28
CVE-2021-4191 [MEDIUM] CVE-2021-4191: An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with rest CVE-2021-4191: An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.
gitlab
CVE-2022-0751MEDIUMCVSS 6.52022-03-28
CVE-2022-0751 [MEDIUM] CVE-2022-0751: Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleadin CVE-2022-0751: Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleading content which could trick unsuspecting users into executing arbitrary commands
gitlab
CVE-2022-0371MEDIUMCVSS 4.32022-03-28
CVE-2022-0371 [MEDIUM] CVE-2022-0371: An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, a CVE-2022-0371: An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails
gitlab