Vulnerabilities > Gitlab > Gitlab > 14.0.9

DATE CVE VULNERABILITY TITLE RISK
2021-12-13 CVE-2021-39940 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
network
low complexity
gitlab
6.5
2021-12-13 CVE-2021-39941 Information Exposure vulnerability in Gitlab
An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members
network
low complexity
gitlab CWE-200
5.0
2021-12-13 CVE-2021-39944 Improper Privilege Management vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
network
low complexity
gitlab CWE-269
5.5
2021-12-13 CVE-2021-39945 Incorrect Authorization vulnerability in Gitlab
Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked
network
low complexity
gitlab CWE-863
4.0
2021-11-05 CVE-2021-39895 Unspecified vulnerability in Gitlab
In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project.
network
high complexity
gitlab
2.1
2021-11-05 CVE-2021-39898 Information Exposure vulnerability in Gitlab
In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from.
network
low complexity
gitlab CWE-200
5.0
2021-11-05 CVE-2021-39901 Unspecified vulnerability in Gitlab
In all versions of GitLab CE/EE since version 11.10, an admin of a group can see the SCIM token of that group by visiting a specific endpoint.
network
low complexity
gitlab
4.0
2021-11-05 CVE-2021-39904 Incorrect Authorization vulnerability in Gitlab
An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request
network
low complexity
gitlab CWE-863
4.3
2021-11-05 CVE-2021-39905 Unspecified vulnerability in Gitlab
An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with
network
low complexity
gitlab
4.0
2021-11-05 CVE-2021-39906 Cross-site Scripting vulnerability in Gitlab
Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.
network
gitlab CWE-79
4.3