Vulnerabilities > Gitlab > Gitlab > 14.10.4

DATE CVE VULNERABILITY TITLE RISK
2022-07-01 CVE-2022-2235 Cross-site Scripting vulnerability in Gitlab
Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link
network
gitlab CWE-79
3.5
2022-07-01 CVE-2022-2243 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.
network
low complexity
gitlab CWE-639
4.3
2022-07-01 CVE-2022-2244 Unspecified vulnerability in Gitlab
An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows project memebers with reporter role to manage issues in project's error tracking feature.
network
low complexity
gitlab
4.3
2022-07-01 CVE-2022-2281 Unspecified vulnerability in Gitlab
An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.
network
gitlab
4.3
2021-06-24 CVE-2021-32823 In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability.
network
high complexity
bindata-project gitlab
3.7