CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Vendor: gitlab
1,044 result(s) · page 32 of 53
CVE-2021-39885
MEDIUM

A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting ...

CVSS 5.4 Gitlab gitlab 2021-10-04
CVE-2021-22259
MEDIUM

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

CVSS 6.5 Gitlab gitlab 2021-10-04
CVE-2021-22244
MEDIUM

Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data

CVSS 6.5 Gitlab gitlab 2021-08-25
CVE-2021-22250
MEDIUM

Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account

CVSS 5.4 Gitlab gitlab 2021-08-25
CVE-2021-22256
MEDIUM

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

CVSS 5.4 Gitlab gitlab 2021-08-25
CVE-2021-22236
HIGH

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since...

CVSS 8.8 Gitlab gitlab 2021-08-25
CVE-2021-22242
MEDIUM

Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-cr...

CVSS 5.4 Gitlab gitlab 2021-08-25
CVE-2021-22252
MEDIUM

A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to M...

CVSS 6.5 Gitlab gitlab 2021-08-23
CVE-2021-22253
MEDIUM

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under ...

CVSS 5.4 Gitlab gitlab 2021-08-23
CVE-2021-22248
MEDIUM

Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects tha...

CVSS 5.3 Gitlab gitlab 2021-08-23
CVE-2021-22246
MEDIUM

A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of service attacks.

CVSS 6.5 Gitlab gitlab 2021-08-20
CVE-2021-22238
MEDIUM

An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

CVSS 5.4 Gitlab gitlab 2021-08-20
CVE-2021-22234
MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting f...

CVSS 6.4 Gitlab gitlab 2021-08-05
CVE-2021-22241
MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default ...

CVSS 5.4 Gitlab gitlab 2021-08-05
CVE-2021-22224
MEDIUM

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the vict...

CVSS 6.5 Gitlab gitlab 2021-07-07
CVE-2021-22225
MEDIUM

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdow...

CVSS 5.4 Gitlab gitlab 2021-07-07
CVE-2021-22230
HIGH

Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, ...

CVSS 7.2 Gitlab gitlab 2021-07-07
CVE-2021-22227
MEDIUM

A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on th...

CVSS 6.1 Gitlab gitlab 2021-07-07
CVE-2021-22228
MEDIUM

An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2. Im...

CVSS 6.5 Gitlab gitlab 2021-07-06
CVE-2021-22223
MEDIUM

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via cl...

CVSS 6.1 Gitlab gitlab 2021-07-06
1 30 31 32 33 34 53
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.