Vulnerabilities > Gitlab > Gitlab > 8.17.5

DATE CVE VULNERABILITY TITLE RISK
2021-12-13 CVE-2021-39931 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
network
gitlab
3.5
2021-12-13 CVE-2021-39937 Improper Privilege Management vulnerability in Gitlab
A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances
network
low complexity
gitlab CWE-269
6.5
2021-12-13 CVE-2021-39938 Resource Exhaustion vulnerability in Gitlab
A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands
network
low complexity
gitlab CWE-400
4.0
2021-11-05 CVE-2021-39895 Unspecified vulnerability in Gitlab
In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project.
network
high complexity
gitlab
2.1
2021-11-05 CVE-2021-39905 Unspecified vulnerability in Gitlab
An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with
network
low complexity
gitlab
4.0
2021-11-05 CVE-2021-39913 Unspecified vulnerability in Gitlab
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges
local
low complexity
gitlab
6.7
2021-11-04 CVE-2021-39914 Resource Exhaustion vulnerability in Gitlab
A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user
network
low complexity
gitlab CWE-400
5.0
2021-10-05 CVE-2021-22258 Unspecified vulnerability in Gitlab
The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses
network
low complexity
gitlab
4.0
2021-10-05 CVE-2021-39881 Unspecified vulnerability in Gitlab
In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.
network
gitlab
3.5
2021-10-05 CVE-2021-39891 Improper Cross-boundary Removal of Sensitive Data vulnerability in Gitlab
In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.
network
low complexity
gitlab CWE-212
4.0