Vulnerabilities > Gitlab > Gitlab > 8.4.8

DATE CVE VULNERABILITY TITLE RISK
2021-03-02 CVE-2021-22187 Resource Exhaustion vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7.
network
low complexity
gitlab CWE-400
4.0
2020-12-11 CVE-2020-26416 Information Exposure vulnerability in Gitlab
Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs.
local
low complexity
gitlab CWE-200
2.1
2020-11-17 CVE-2020-13350 Cross-Site Request Forgery (CSRF) vulnerability in Gitlab
CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners.
network
gitlab CWE-352
4.3
2020-10-08 CVE-2020-13340 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log
network
gitlab CWE-79
3.5
2020-10-08 CVE-2020-13339 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions before 13.2.10, 13.3.7 and 13.4.2: XSS in SVG File Preview.
network
gitlab CWE-79
6.0
2020-10-07 CVE-2020-13335 Improper Authentication vulnerability in Gitlab
Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.
network
low complexity
gitlab CWE-287
4.0
2020-09-30 CVE-2020-13331 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting versions prior to 12.10.13.
network
gitlab CWE-79
3.5
2020-09-30 CVE-2020-13330 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting versions prior to 12.10.13.
network
gitlab CWE-79
3.5
2020-09-30 CVE-2020-13329 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13.
network
gitlab CWE-79
3.5
2020-09-30 CVE-2020-13321 Unspecified vulnerability in Gitlab
A vulnerability was discovered in GitLab versions prior to 13.1.
network
low complexity
gitlab
6.5