Vulnerabilities > Gitlab > Gitlab > 13.0.14

DATE CVE VULNERABILITY TITLE RISK
2022-03-28 CVE-2022-0136 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1.
network
low complexity
gitlab CWE-918
5.5
2022-03-28 CVE-2022-0249 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A vulnerability was discovered in GitLab starting with version 12.
network
low complexity
gitlab CWE-918
6.4
2022-03-28 CVE-2022-0344 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1.
network
gitlab
4.3
2021-12-06 CVE-2021-22170 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Gitlab
Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content
network
low complexity
gitlab CWE-327
5.0
2021-07-07 CVE-2021-22227 Cross-site Scripting vulnerability in Gitlab
A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it
network
gitlab CWE-79
4.3
2021-07-06 CVE-2021-22228 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2.
network
low complexity
gitlab
4.0
2021-07-06 CVE-2021-22229 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8.
network
gitlab
4.3
2021-06-08 CVE-2021-22214 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited
network
gitlab CWE-918
4.3
2020-09-14 CVE-2020-13304 Improper Authentication vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-287
6.5
2020-09-14 CVE-2020-13298 Improper Input Validation vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-20
5.0