Vulnerabilities > Gitlab > Gitlab > 13.12.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-08-20 | CVE-2021-22246 | Allocation of Resources Without Limits or Throttling vulnerability in Gitlab A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. | 4.0 |
2021-08-20 | CVE-2021-22254 | Improper Encoding or Escaping of Output vulnerability in Gitlab Under very specific conditions a user could be impersonated using Gitlab shell. | 3.5 |
2021-08-05 | CVE-2021-22234 | Cross-site Scripting vulnerability in Gitlab An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. | 3.5 |
2021-08-05 | CVE-2021-22240 | Incorrect Authorization vulnerability in Gitlab Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled | 4.0 |
2021-07-07 | CVE-2021-22233 | Missing Authorization vulnerability in Gitlab An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details | 4.0 |
2021-07-07 | CVE-2021-22224 | Cross-Site Request Forgery (CSRF) vulnerability in Gitlab A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim | 4.3 |
2021-07-07 | CVE-2021-22225 | Cross-site Scripting vulnerability in Gitlab Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown | 3.5 |
2021-07-07 | CVE-2021-22230 | Unspecified vulnerability in Gitlab Improper code rendering while rendering merge requests could be exploited to submit malicious code. | 6.5 |
2021-07-07 | CVE-2021-22231 | Unspecified vulnerability in Gitlab A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username. | 4.0 |
2021-07-06 | CVE-2021-22223 | Cross-site Scripting vulnerability in Gitlab Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link | 4.3 |