Vulnerabilities > Gitlab

DATE CVE VULNERABILITY TITLE RISK
2022-07-01 CVE-2022-2227 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions
network
low complexity
gitlab CWE-732
4.3
2022-07-01 CVE-2022-2230 Cross-site Scripting vulnerability in Gitlab
A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.
network
low complexity
gitlab CWE-79
4.8
2022-07-01 CVE-2022-2235 Cross-site Scripting vulnerability in Gitlab
Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link
network
low complexity
gitlab CWE-79
5.4
2022-07-01 CVE-2022-2243 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.
network
low complexity
gitlab CWE-639
4.3
2022-07-01 CVE-2022-2244 Unspecified vulnerability in Gitlab
An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows project memebers with reporter role to manage issues in project's error tracking feature.
network
low complexity
gitlab
4.3
2022-07-01 CVE-2022-2250 Open Redirect vulnerability in Gitlab
An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.
network
low complexity
gitlab CWE-601
6.1
2022-07-01 CVE-2022-2281 Unspecified vulnerability in Gitlab
An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.
network
low complexity
gitlab
5.3
2022-06-06 CVE-2022-1680 Unspecified vulnerability in Gitlab
An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1.
network
low complexity
gitlab
8.8
2022-06-06 CVE-2021-39947 Unspecified vulnerability in Gitlab Runner
In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2 would re-use the file descriptor 0 for multiple traces and mix the output of several jobs
network
low complexity
gitlab
7.5
2022-06-06 CVE-2022-1783 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1.
network
low complexity
gitlab
2.7