Vulnerabilities > Gitlab

DATE CVE VULNERABILITY TITLE RISK
2022-08-05 CVE-2022-2497 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab
6.4
2022-08-05 CVE-2022-2498 Improper Privilege Management vulnerability in Gitlab
An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.
network
low complexity
gitlab CWE-269
7.5
2022-08-05 CVE-2022-2499 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab CWE-639
4.3
2022-08-05 CVE-2022-2500 Cross-site Scripting vulnerability in Gitlab
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1.
network
low complexity
gitlab CWE-79
5.4
2022-08-05 CVE-2022-2501 Incorrect Authorization vulnerability in Gitlab
An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an attacker to bypass IP allow-listing and download artifacts.
network
low complexity
gitlab CWE-863
7.5
2022-08-05 CVE-2022-2512 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab
6.5
2022-08-05 CVE-2022-2531 Path Traversal vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab CWE-22
5.3
2022-08-05 CVE-2022-2534 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab
5.3
2022-08-05 CVE-2022-2539 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.6 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1, allowed a project member to filter issues by contact and organization.
network
low complexity
gitlab
5.3
2022-07-28 CVE-2022-1948 Cross-site Scripting vulnerability in Gitlab 15.0.0
An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1.
network
low complexity
gitlab CWE-79
5.4