Gitlab Ce vulnerabilities

572 known vulnerabilities affecting gitlab/gitlab_ce.

Total CVEs
572
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL18HIGH128MEDIUM342LOW84

Vulnerabilities

Page 22 of 29
CVE-2022-0488LOWCVSS 3.52022-03-28
CVE-2022-0488 [LOW] CWE-400 CVE-2022-0488: An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with ma CVE-2022-0488: An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes.
gitlab
CVE-2021-39946HIGHCVSS 8.72022-01-18
CVE-2021-39946 [HIGH] CWE-79 CVE-2021-39946: Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS b CVE-2021-39946: Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis
gitlab
CVE-2022-0244HIGHCVSS 8.62022-01-18
CVE-2022-0244 [HIGH] CWE-552 CVE-2022-0244: An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due CVE-2022-0244: An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.
gitlab
CVE-2021-39892MEDIUMCVSS 4.32022-01-18
CVE-2021-39892 [MEDIUM] CVE-2021-39892: In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a maintainer role on a CVE-2021-39892: In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a maintainer role on and disclose email addresses of those users.
gitlab
CVE-2022-0172MEDIUMCVSS 5.32022-01-18
CVE-2022-0172 [MEDIUM] CVE-2022-0172: An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP rest CVE-2022-0172: An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.
gitlab
CVE-2021-39942MEDIUMCVSS 4.32022-01-18
CVE-2021-39942 [MEDIUM] CWE-400 CVE-2021-39942: A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4 CVE-2021-39942: A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository
gitlab
CVE-2021-39927LOWCVSS 3.52022-01-18
CVE-2021-39927 [LOW] CWE-918 CVE-2021-39927: Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and between 14.6.0 and 14.6.1 woul CVE-2021-39927: Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and between 14.6.0 and 14.6.1 would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configured to run on a port other than 80
gitlab
CVE-2021-39944HIGHCVSS 7.12021-12-13
CVE-2021-39944 [HIGH] CWE-269 CVE-2021-39944: An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, a CVE-2021-39944: An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their
gitlab
CVE-2021-39940MEDIUMCVSS 4.32021-12-13
CVE-2021-39940 [MEDIUM] CWE-1333 CVE-2021-39940: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, a CVE-2021-39940: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service wh
gitlab
CVE-2021-39919MEDIUMCVSS 4.42021-12-13
CVE-2021-39919 [MEDIUM] CWE-640 CVE-2021-39919: In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 be CVE-2021-39919: In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.
gitlab
CVE-2021-39933MEDIUMCVSS 4.32021-12-13
CVE-2021-39933 [MEDIUM] CWE-1333 CVE-2021-39933: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, CVE-2021-39933: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible
gitlab
CVE-2021-39932MEDIUMCVSS 4.32021-12-13
CVE-2021-39932 [MEDIUM] CWE-20 CVE-2021-39932: An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, a CVE-2021-39932: An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for users r
gitlab
CVE-2021-39935MEDIUMCVSS 6.8KEVPoC2021-12-13
CVE-2021-39935 [MEDIUM] CWE-918 CVE-2021-39935: An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, a CVE-2021-39935: An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API CISA
gitlab
CVE-2021-39937MEDIUMCVSS 5.92021-12-13
CVE-2021-39937 [MEDIUM] CWE-269 CVE-2021-39937: A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions sta CVE-2021-39937: A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances
gitlab
CVE-2021-39934MEDIUMCVSS 4.32021-12-13
CVE-2021-39934 [MEDIUM] CWE-639 CVE-2021-39934: Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, al CVE-2021-39934: Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
gitlab
CVE-2021-39915MEDIUMCVSS 5.32021-12-13
CVE-2021-39915 [MEDIUM] CWE-668 CVE-2021-39915: Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 be CVE-2021-39915: Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary p
gitlab
CVE-2021-39917MEDIUMCVSS 4.32021-12-13
CVE-2021-39917 [MEDIUM] CWE-697 CVE-2021-39917: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, a CVE-2021-39917: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression related to quick actions features was susceptible to catastrophic ba
gitlab
CVE-2021-39936LOWCVSS 3.52021-12-13
CVE-2021-39936 [LOW] CWE-863 CVE-2021-39936: Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all ve CVE-2021-39936: Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.
gitlab
CVE-2021-39938LOWCVSS 3.12021-12-13
CVE-2021-39938 [LOW] CWE-400 CVE-2021-39938: A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions CVE-2021-39938: A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially
gitlab
CVE-2021-39910LOWCVSS 2.62021-12-13
CVE-2021-39910 [LOW] CWE-79 CVE-2021-39910: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, a CVE-2021-39910: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.
gitlab