Vulnerabilities > Gitlab > Gitlab > 15.2

DATE CVE VULNERABILITY TITLE RISK
2022-11-09 CVE-2022-3265 Cross-site Scripting vulnerability in Gitlab
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2.
network
low complexity
gitlab CWE-79
5.4
2022-11-09 CVE-2022-3280 Open Redirect vulnerability in Gitlab
An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.
network
low complexity
gitlab CWE-601
6.1
2022-11-09 CVE-2022-3285 Unspecified vulnerability in Gitlab
Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab
network
low complexity
gitlab
7.5
2022-11-09 CVE-2022-3483 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2.
network
low complexity
gitlab
5.4
2022-11-09 CVE-2022-3486 Open Redirect vulnerability in Gitlab
An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.
network
low complexity
gitlab CWE-601
6.1
2022-11-02 CVE-2022-2904 Cross-site Scripting vulnerability in Gitlab
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 It was possible to exploit a vulnerability in the external status checks feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.
network
low complexity
gitlab CWE-79
5.4
2022-10-28 CVE-2022-2882 Exposure of Resource to Wrong Sphere vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1.
network
low complexity
gitlab CWE-668
4.3
2022-10-28 CVE-2022-3018 Information Exposure Through Log Files vulnerability in Gitlab
An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to access the DataDog integration API key from webhook logs.
network
low complexity
gitlab CWE-532
4.9
2022-10-21 CVE-2022-3639 Resource Exhaustion vulnerability in Gitlab
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.
network
low complexity
gitlab CWE-400
7.5
2022-10-17 CVE-2022-2428 Cross-site Scripting vulnerability in Gitlab
A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests
network
low complexity
gitlab CWE-79
7.3