Gitlab Ce vulnerabilities

572 known vulnerabilities affecting gitlab/gitlab_ce.

Total CVEs
572
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL18HIGH128MEDIUM342LOW84

Vulnerabilities

Page 26 of 29
CVE-2021-22219MEDIUMCVSS 4.42021-06-08
CVE-2021-22219 [MEDIUM] CWE-532 CVE-2021-22219: All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 b CVE-2021-22219: All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not corr
gitlab
CVE-2021-22218LOWCVSS 2.62021-06-08
CVE-2021-22218 [LOW] CWE-295 CVE-2021-22218: All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 CVE-2021-22218: All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.
gitlab
CVE-2021-22209HIGHCVSS 7.52021-05-06
CVE-2021-22209 [HIGH] CWE-863 CVE-2021-22209: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which CVE-2021-22209: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.
gitlab
CVE-2021-22210MEDIUMCVSS 5.32021-05-06
CVE-2021-22210 [MEDIUM] CWE-770 CVE-2021-22210: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was CVE-2021-22210: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.
gitlab
CVE-2021-22211LOWCVSS 3.12021-05-06
CVE-2021-22211 [LOW] CWE-863 CVE-2021-22211: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impe CVE-2021-22211: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.
gitlab
CVE-2021-22205CRITICALCVSS 10.0KEVPoC2021-04-23
CVE-2021-22205 [CRITICAL] CWE-94 CVE-2021-22205: An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passe CVE-2021-22205: An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution. CISA KEV: GitHub Community and Enterprise Editions that utilize the
gitlab
CVE-2021-22201CRITICALCVSS 9.62021-04-02
CVE-2021-22201 [CRITICAL] CVE-2021-22201: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server CVE-2021-22201: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server.
gitlab
CVE-2021-22203HIGHCVSS 7.52021-04-02
CVE-2021-22203 [HIGH] CVE-2021-22203: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7.9 before 13.8.7, all versions starting from 13.9 before 13.9.5, CVE-2021-22203: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7.9 before 13.8.7, all versions starting from 13.9 before 13.9.5, and all versions starting from 13.10 before 13.10.1. A specially crafted Wiki page allowed attackers to read arbitrary files on the server.
gitlab
CVE-2021-22200MEDIUMCVSS 5.92021-04-02
CVE-2021-22200 [MEDIUM] CVE-2021-22200: An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an CVE-2021-22200: An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an internal repository through a public project fork as an anonymous user.
gitlab
CVE-2021-22196MEDIUMCVSS 6.32021-04-02
CVE-2021-22196 [MEDIUM] CWE-79 CVE-2021-22196: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in me CVE-2021-22196: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in merge request via a specifically crafted branch name.
gitlab
CVE-2021-22198MEDIUMCVSS 4.32021-04-02
CVE-2021-22198 [MEDIUM] CVE-2021-22198: An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric image CVE-2021-22198: An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects.
gitlab
CVE-2021-22197LOWCVSS 3.52021-04-02
CVE-2021-22197 [LOW] CWE-835 CVE-2021-22197: An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 where an infinite loop exist when an authenticated user with sp CVE-2021-22197: An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 where an infinite loop exist when an authenticated user with specific rights access a MR having source and target branch pointing to each other
gitlab
CVE-2021-22202LOWCVSS 2.42021-04-02
CVE-2021-22202 [LOW] CWE-352 CVE-2021-22202: An issue has been discovered in GitLab CE/EE affecting all previous versions. If the victim is an admin, it was possible to issue a CSRF in System hoo CVE-2021-22202: An issue has been discovered in GitLab CE/EE affecting all previous versions. If the victim is an admin, it was possible to issue a CSRF in System hooks through the API.
gitlab
CVE-2021-22177MEDIUMCVSS 4.32021-04-01
CVE-2021-22177 [MEDIUM] CWE-400 CVE-2021-22177: Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilizatio CVE-2021-22177: Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.
gitlab
CVE-2021-22192CRITICALCVSS 9.92021-03-24
CVE-2021-22192 [CRITICAL] CVE-2021-22192: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary CVE-2021-22192: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server.
gitlab
CVE-2021-22186MEDIUMCVSS 4.92021-03-24
CVE-2021-22186 [MEDIUM] CWE-863 CVE-2021-22186: An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to gro CVE-2021-22186: An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners
gitlab
CVE-2021-22189MEDIUMCVSS 5.92021-03-04
CVE-2021-22189 [MEDIUM] CWE-295 CVE-2021-22189: Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet CVE-2021-22189: Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.
gitlab
CVE-2020-26409MEDIUMCVSS 4.32020-12-11
CVE-2020-26409 [MEDIUM] CWE-20 CVE-2020-26409: A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by CVE-2020-26409: A DOS vulnerability exists in Gitlab CE/EE >=10.3, =13.5, =13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.
gitlab
CVE-2020-26417MEDIUMCVSS 5.32020-12-11
CVE-2020-26417 [MEDIUM] CWE-200 CVE-2020-26417: Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6. CVE-2020-26417: Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to =13.5 to =13.1 to <13.4.7.
gitlab
CVE-2020-13357MEDIUMCVSS 4.32020-12-11
CVE-2020-13357 [MEDIUM] CWE-639 CVE-2020-13357: An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access CVE-2020-13357: An issue was discovered in Gitlab CE/EE versions >= 13.1 to = 13.5 to = 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.
gitlab