Vulnerabilities > Gitlab > Gitlab > 14.7.1

DATE CVE VULNERABILITY TITLE RISK
2022-04-01 CVE-2022-0425 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.
network
low complexity
gitlab CWE-918
6.5
2022-04-01 CVE-2022-0489 Resource Exhaustion vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 .
network
gitlab CWE-400
3.5
2022-04-01 CVE-2022-0741 Improper Encoding or Escaping of Output vulnerability in Gitlab
Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables via specially crafted email addresses.
network
low complexity
gitlab CWE-116
7.5
2022-03-28 CVE-2021-4191 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2.
network
low complexity
gitlab
5.0
2022-03-28 CVE-2022-0136 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1.
network
low complexity
gitlab CWE-918
5.5
2022-03-28 CVE-2022-0249 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A vulnerability was discovered in GitLab starting with version 12.
network
low complexity
gitlab CWE-918
6.4
2022-03-28 CVE-2022-0371 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1.
network
low complexity
gitlab
4.0
2022-03-28 CVE-2022-0427 Cross-Site Request Forgery (CSRF) vulnerability in Gitlab
Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover
network
gitlab CWE-352
6.8
2022-03-28 CVE-2022-0488 Resource Exhaustion vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10.
network
low complexity
gitlab CWE-400
4.0
2022-03-28 CVE-2022-0549 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
network
gitlab
3.5