Vulnerabilities > Gitlab > Gitlab > 14.5

DATE CVE VULNERABILITY TITLE RISK
2022-05-11 CVE-2022-1406 Improper Input Validation vulnerability in Gitlab
Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project
network
low complexity
gitlab CWE-20
4.0
2022-05-11 CVE-2022-1426 Improper Authentication vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
gitlab CWE-287
4.3
2022-05-11 CVE-2022-1428 Allocation of Resources Without Limits or Throttling vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
low complexity
gitlab CWE-770
4.0
2022-05-11 CVE-2022-1433 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
gitlab CWE-79
4.3
2022-05-11 CVE-2022-1460 Incorrect Authorization vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
low complexity
gitlab CWE-863
4.9
2022-05-11 CVE-2022-1510 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
low complexity
gitlab
7.5
2022-05-11 CVE-2022-1545 Unspecified vulnerability in Gitlab
It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.
network
low complexity
gitlab
4.3
2022-05-10 CVE-2022-1417 Incorrect Authorization vulnerability in Gitlab
Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access contents of Project Members-only Wikis via malicious CI jobs
network
low complexity
gitlab CWE-863
4.0
2022-05-10 CVE-2022-1431 Improper Input Validation vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
low complexity
gitlab CWE-20
5.3
2022-04-25 CVE-2022-0477 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1.
network
low complexity
gitlab
4.0