Vulnerabilities > Gitlab > Gitlab > 15.0.4

DATE CVE VULNERABILITY TITLE RISK
2022-10-28 CVE-2022-2882 Exposure of Resource to Wrong Sphere vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1.
network
low complexity
gitlab CWE-668
4.3
2022-10-28 CVE-2022-3018 Information Exposure Through Log Files vulnerability in Gitlab
An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to access the DataDog integration API key from webhook logs.
network
low complexity
gitlab CWE-532
4.9
2022-10-21 CVE-2022-3639 Resource Exhaustion vulnerability in Gitlab
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.
network
low complexity
gitlab CWE-400
7.5
2022-10-17 CVE-2022-2428 Cross-site Scripting vulnerability in Gitlab
A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests
network
low complexity
gitlab CWE-79
7.3
2022-10-17 CVE-2022-2455 Resource Exhaustion vulnerability in Gitlab
A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an authenticated and authorized user to exhaust server resources by importing a malicious project.
network
low complexity
gitlab CWE-400
6.5
2022-10-17 CVE-2022-2527 Cross-site Scripting vulnerability in Gitlab
An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content.
network
low complexity
gitlab CWE-79
8.0
2022-10-17 CVE-2022-2533 Improper Authentication vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.
network
high complexity
gitlab CWE-287
7.4
2022-10-17 CVE-2022-2592 Improper Validation of Specified Quantity in Input vulnerability in Gitlab
A lack of length validation in Snippet descriptions in GitLab CE/EE affecting all versions prior to 15.1.6, 15.2 prior to 15.2.4 and 15.3 prior to 15.3.2 allows an authenticated attacker to create a maliciously large Snippet which when requested with or without authentication places excessive load on the server, potential leading to Denial of Service.
network
low complexity
gitlab CWE-1284
6.5
2022-10-17 CVE-2022-2865 Cross-site Scripting vulnerability in Gitlab
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2.
network
low complexity
gitlab CWE-79
4.8
2022-10-17 CVE-2022-2884 OS Command Injection vulnerability in Gitlab
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint
network
low complexity
gitlab CWE-78
critical
9.9