Vulnerabilities > Gitlab

DATE CVE VULNERABILITY TITLE RISK
2022-01-18 CVE-2022-0124 Improper Encoding or Escaping of Output vulnerability in Gitlab
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1.
network
low complexity
gitlab CWE-116
4.3
2022-01-18 CVE-2022-0125 Missing Authorization vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2.
network
low complexity
gitlab CWE-862
4.3
2022-01-18 CVE-2022-0151 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2.
network
low complexity
gitlab
4.9
2022-01-18 CVE-2022-0152 Missing Authorization vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2.
network
low complexity
gitlab CWE-862
6.5
2022-01-18 CVE-2022-0154 Cross-Site Request Forgery (CSRF) vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2.
network
low complexity
gitlab CWE-352
8.0
2022-01-18 CVE-2022-0172 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3.
network
low complexity
gitlab
6.5
2022-01-18 CVE-2022-0244 Files or Directories Accessible to External Parties vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5.
network
low complexity
gitlab CWE-552
7.5
2021-12-13 CVE-2021-39910 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
network
low complexity
gitlab CWE-79
4.3
2021-12-13 CVE-2021-39915 Exposure of Resource to Wrong Sphere vulnerability in Gitlab
Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects
network
low complexity
gitlab CWE-668
5.3
2021-12-13 CVE-2021-39916 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
network
low complexity
gitlab CWE-639
4.3