Vulnerabilities > Gitlab > Gitlab > 14.7.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-04-04 | CVE-2022-1190 | Cross-site Scripting vulnerability in Gitlab Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc. | 3.5 |
2022-04-01 | CVE-2022-0373 | Unspecified vulnerability in Gitlab Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address | 4.3 |
2022-04-01 | CVE-2022-0390 | Missing Authorization vulnerability in Gitlab Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard. | 4.3 |
2022-04-01 | CVE-2022-0425 | Server-Side Request Forgery (SSRF) vulnerability in Gitlab A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks. | 6.5 |
2022-04-01 | CVE-2022-0489 | Resource Exhaustion vulnerability in Gitlab An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . | 3.5 |
2022-04-01 | CVE-2022-0741 | Improper Encoding or Escaping of Output vulnerability in Gitlab Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables via specially crafted email addresses. | 7.5 |
2022-03-28 | CVE-2021-4191 | Unspecified vulnerability in Gitlab An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. | 5.0 |
2022-03-28 | CVE-2022-0136 | Server-Side Request Forgery (SSRF) vulnerability in Gitlab A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. | 5.5 |
2022-03-28 | CVE-2022-0249 | Server-Side Request Forgery (SSRF) vulnerability in Gitlab A vulnerability was discovered in GitLab starting with version 12. | 6.4 |
2022-03-28 | CVE-2022-0344 | Unspecified vulnerability in Gitlab An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. network gitlab | 4.3 |