GitLab / Gitlab EE
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-22240 | Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled | MEDIUM | 4.3 | Aug 5, 2021 |
| CVE-2020-26412 | Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2. | MEDIUM | 4.3 | Dec 11, 2020 |
| CVE-2020-26416 | Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=… | MEDIUM | 4.4 | Dec 11, 2020 |
| CVE-2020-13349 | An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted in the Advanced Searc… | MEDIUM | 4.3 | Nov 17, 2020 |
| CVE-2020-13348 | An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch witho… | MEDIUM | 5.7 | Nov 17, 2020 |
| CVE-2020-26406 | Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to… | MEDIUM | 5.3 | Nov 17, 2020 |
| CVE-2019-15581 | An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or maintainer to… | MEDIUM | 5.3 | Jan 28, 2020 |
| CVE-2019-15582 | An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer to add any… | MEDIUM | 5.3 | Jan 28, 2020 |
| CVE-2019-15590 | An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests… | HIGH | 7.5 | Jan 28, 2020 |
| CVE-2019-5474 | An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropr… | MEDIUM | 6.5 | Jan 28, 2020 |
Showing 1 to 10 of 10 CVEs