Vulnerabilities > Gitlab > Gitlab > 14.9.1

DATE CVE VULNERABILITY TITLE RISK
2022-05-11 CVE-2022-1428 Allocation of Resources Without Limits or Throttling vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
low complexity
gitlab CWE-770
4.0
2022-05-11 CVE-2022-1433 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
gitlab CWE-79
4.3
2022-05-11 CVE-2022-1460 Incorrect Authorization vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
low complexity
gitlab CWE-863
4.9
2022-05-11 CVE-2022-1510 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
low complexity
gitlab
7.5
2022-05-11 CVE-2022-1545 Unspecified vulnerability in Gitlab
It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.
network
low complexity
gitlab
4.3
2022-05-10 CVE-2022-1417 Incorrect Authorization vulnerability in Gitlab
Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access contents of Project Members-only Wikis via malicious CI jobs
network
low complexity
gitlab CWE-863
4.0
2022-05-10 CVE-2022-1431 Improper Input Validation vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
low complexity
gitlab CWE-20
5.3
2022-04-11 CVE-2022-1157 Information Exposure Through Log Files vulnerability in Gitlab
Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged
network
gitlab CWE-532
3.5
2022-04-11 CVE-2022-1193 Incorrect Authorization vulnerability in Gitlab
Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances
network
low complexity
gitlab CWE-863
4.3
2022-04-04 CVE-2022-0740 Incorrect Authorization vulnerability in Gitlab
Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.
network
low complexity
gitlab CWE-863
4.0