Vulnerabilities > Gitlab > Gitlab > 7.8.4

DATE CVE VULNERABILITY TITLE RISK
2022-10-17 CVE-2022-3031 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.
network
low complexity
gitlab
7.5
2022-10-17 CVE-2022-3060 Path Traversal vulnerability in Gitlab
Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests
network
low complexity
gitlab CWE-22
7.3
2022-10-17 CVE-2022-3279 Improper Handling of Exceptional Conditions vulnerability in Gitlab
An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs
network
low complexity
gitlab CWE-755
6.5
2022-10-17 CVE-2022-3283 Resource Exhaustion vulnerability in Gitlab
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 While cloning an issue with special crafted content added to the description could have been used to trigger high CPU usage.
network
low complexity
gitlab CWE-400
7.5
2022-10-17 CVE-2022-3288 Unspecified vulnerability in Gitlab
A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.
network
low complexity
gitlab
4.3
2022-08-05 CVE-2022-2303 Improper Authentication vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab CWE-287
4.3
2022-08-05 CVE-2022-2456 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab
2.7
2022-08-05 CVE-2022-2459 Missing Authorization vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab CWE-862
2.7
2022-07-01 CVE-2022-1954 Unspecified vulnerability in Gitlab
A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to make a GitLab instance inaccessible via specially crafted web server response headers
network
low complexity
gitlab
5.3
2022-07-01 CVE-2022-2227 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions
network
gitlab CWE-732
3.5