Vulnerabilities > Gitlab > Gitlab > 14.7.7

DATE CVE VULNERABILITY TITLE RISK
2022-05-19 CVE-2022-1416 Cross-site Scripting vulnerability in Gitlab
Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling
network
gitlab CWE-79
3.5
2022-05-19 CVE-2022-1423 Missing Authorization vulnerability in Gitlab
Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches
network
low complexity
gitlab CWE-862
8.8
2022-05-11 CVE-2022-1124 Incorrect Authorization vulnerability in Gitlab
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled
network
gitlab CWE-863
3.5
2022-05-11 CVE-2022-1352 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members.
network
low complexity
gitlab CWE-639
5.0
2022-05-11 CVE-2022-1406 Improper Input Validation vulnerability in Gitlab
Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project
network
low complexity
gitlab CWE-20
4.0
2022-05-11 CVE-2022-1426 Improper Authentication vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
gitlab CWE-287
4.3
2022-05-11 CVE-2022-1428 Allocation of Resources Without Limits or Throttling vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
low complexity
gitlab CWE-770
4.0
2022-05-11 CVE-2022-1433 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
gitlab CWE-79
4.3
2022-05-11 CVE-2022-1460 Incorrect Authorization vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
low complexity
gitlab CWE-863
4.9
2022-05-11 CVE-2022-1510 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
low complexity
gitlab
7.5