Vulnerabilities > Gitlab

DATE CVE VULNERABILITY TITLE RISK
2023-04-05 CVE-2022-3375 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1.
network
high complexity
gitlab
3.7
2023-04-05 CVE-2022-3513 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1.
network
low complexity
gitlab CWE-79
6.1
2023-04-05 CVE-2023-0319 Incorrect Authorization vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only.
network
low complexity
gitlab CWE-863
5.3
2023-04-05 CVE-2023-0523 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1.
network
low complexity
gitlab CWE-79
6.1
2023-04-05 CVE-2023-1098 Unspecified vulnerability in Gitlab
An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configuration.
network
low complexity
gitlab
4.9
2023-04-05 CVE-2023-1733 Unspecified vulnerability in Gitlab
A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1.
network
low complexity
gitlab
7.5
2023-03-27 CVE-2023-0326 Unspecified vulnerability in Gitlab Dynamic Application Security Testing Analyzer
An issue has been discovered in GitLab DAST API scanner affecting all versions starting from 1.6.50 before 2.11.0, where Authorization headers was leaked in vulnerability report evidence.
network
low complexity
gitlab
4.3
2023-03-09 CVE-2022-3758 Incorrect Default Permissions vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2.
network
low complexity
gitlab CWE-276
5.4
2023-03-09 CVE-2022-3767 Unspecified vulnerability in Gitlab Dynamic Application Security Testing Analyzer
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
network
low complexity
gitlab
6.5
2023-03-09 CVE-2022-4331 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2.
network
low complexity
gitlab
7.3