Vulnerabilities > Gitlab > Gitlab > 13.4.7

DATE CVE VULNERABILITY TITLE RISK
2021-01-15 CVE-2021-22171 Improper Authentication vulnerability in Gitlab
Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link
network
gitlab CWE-287
4.3
2021-01-15 CVE-2021-22168 Resource Exhaustion vulnerability in Gitlab
A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.
network
low complexity
gitlab CWE-400
4.0
2021-01-15 CVE-2021-22167 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.1.
network
low complexity
gitlab
5.0
2021-01-15 CVE-2020-26414 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.4.
network
low complexity
gitlab
4.0
2020-12-11 CVE-2020-26412 Information Exposure vulnerability in Gitlab
Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.
network
low complexity
gitlab CWE-200
4.0