Vulnerabilities > Gitlab > Gitlab > 13.7.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-03-24 | CVE-2021-22176 | Incorrect Authorization vulnerability in Gitlab An issue has been discovered in GitLab affecting all versions starting with 3.0.1. | 4.0 |
2021-03-04 | CVE-2021-22189 | Improper Certificate Validation vulnerability in Gitlab Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues. | 6.5 |
2021-03-04 | CVE-2021-22183 | Cross-site Scripting vulnerability in Gitlab An issue has been discovered in GitLab affecting all versions starting with 11.8. | 3.5 |
2021-03-03 | CVE-2021-22188 | Unspecified vulnerability in Gitlab An issue has been discovered in GitLab affecting all versions starting with 13.0. | 5.0 |
2021-03-03 | CVE-2021-22182 | Cross-site Scripting vulnerability in Gitlab 13.7.0/13.7.2 An issue has been discovered in GitLab affecting all versions starting with 13.7. | 3.5 |
2021-03-02 | CVE-2021-22187 | Resource Exhaustion vulnerability in Gitlab An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. | 4.0 |
2021-01-15 | CVE-2021-22171 | Improper Authentication vulnerability in Gitlab Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link | 4.3 |
2021-01-15 | CVE-2021-22168 | Resource Exhaustion vulnerability in Gitlab A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8. | 4.0 |
2021-01-15 | CVE-2021-22167 | Unspecified vulnerability in Gitlab An issue has been discovered in GitLab affecting all versions starting from 12.1. | 5.0 |
2021-01-15 | CVE-2021-22166 | Resource Exhaustion vulnerability in Gitlab 13.7.0 An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method | 5.0 |