Vulnerabilities > Gitlab > Gitlab > 13.3.5

DATE CVE VULNERABILITY TITLE RISK
2021-03-24 CVE-2021-22176 Incorrect Authorization vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting with 3.0.1.
network
low complexity
gitlab CWE-863
4.0
2021-03-04 CVE-2021-22189 Improper Certificate Validation vulnerability in Gitlab
Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.
network
low complexity
gitlab CWE-295
6.5
2021-03-04 CVE-2021-22183 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting with 11.8.
network
gitlab CWE-79
3.5
2021-03-03 CVE-2021-22188 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting with 13.0.
network
low complexity
gitlab
5.0
2021-03-02 CVE-2021-22187 Resource Exhaustion vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7.
network
low complexity
gitlab CWE-400
4.0
2021-01-15 CVE-2021-22171 Improper Authentication vulnerability in Gitlab
Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link
network
gitlab CWE-287
4.3
2021-01-15 CVE-2021-22168 Resource Exhaustion vulnerability in Gitlab
A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.
network
low complexity
gitlab CWE-400
4.0
2021-01-15 CVE-2021-22167 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.1.
network
low complexity
gitlab
5.0
2021-01-15 CVE-2020-26414 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.4.
network
low complexity
gitlab
4.0
2020-12-11 CVE-2020-26417 Information Exposure vulnerability in Gitlab
Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership.
network
low complexity
gitlab CWE-200
5.0