Vulnerabilities > Gitlab > Gitlab > 13.3.1

DATE CVE VULNERABILITY TITLE RISK
2020-09-14 CVE-2020-13298 Improper Input Validation vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-20
5.0
2020-09-14 CVE-2020-13297 Improper Authentication vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
gitlab CWE-287
4.9
2020-09-14 CVE-2020-13317 Improper Input Validation vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4.
network
low complexity
gitlab CWE-20
4.0
2020-09-14 CVE-2020-13314 Unspecified vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab
5.0
2020-09-14 CVE-2020-13313 Incorrect Authorization vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-863
4.0
2020-09-14 CVE-2020-13312 Insufficiently Protected Credentials vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-522
5.0
2020-09-14 CVE-2020-13311 Injection vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-74
4.0
2020-09-14 CVE-2020-13318 Incorrect Authorization vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4.
network
gitlab CWE-863
4.9
2020-09-14 CVE-2020-13316 Missing Authorization vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-862
4.0
2020-09-14 CVE-2020-13300 Incorrect Authorization vulnerability in Gitlab 13.3.0/13.3.1/13.3.2
GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.
network
low complexity
gitlab CWE-863
critical
10.0