Vulnerabilities > Gitlab

DATE CVE VULNERABILITY TITLE RISK
2023-09-01 CVE-2023-0120 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1.
network
low complexity
gitlab
4.3
2023-09-01 CVE-2023-1279 Open Redirect vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 where it was possible to create a URL that would redirect to a different project.
network
low complexity
gitlab CWE-601
6.1
2023-09-01 CVE-2023-1555 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1.
network
low complexity
gitlab
4.3
2023-09-01 CVE-2023-3205 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1.
network
low complexity
gitlab
6.5
2023-09-01 CVE-2023-3210 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1.
network
low complexity
gitlab
6.5
2023-09-01 CVE-2023-3915 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1.
network
low complexity
gitlab CWE-732
7.2
2023-09-01 CVE-2023-3950 Cleartext Storage of Sensitive Information vulnerability in Gitlab
An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured.
network
low complexity
gitlab CWE-312
3.8
2023-09-01 CVE-2023-4018 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1.
network
low complexity
gitlab
5.3
2023-09-01 CVE-2023-4378 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1.
network
low complexity
gitlab
4.3
2023-09-01 CVE-2023-4647 Allocation of Resources Without Limits or Throttling vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.
network
low complexity
gitlab CWE-770
7.5