Vulnerabilities > Gitlab

DATE CVE VULNERABILITY TITLE RISK
2021-03-03 CVE-2021-22188 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting with 13.0.
network
low complexity
gitlab
5.3
2021-03-03 CVE-2021-22182 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting with 13.7.
network
low complexity
gitlab CWE-79
5.4
2021-03-02 CVE-2021-22187 Resource Exhaustion vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7.
network
low complexity
gitlab CWE-400
4.3
2021-01-15 CVE-2021-22171 Improper Authentication vulnerability in Gitlab
Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link
network
low complexity
gitlab CWE-287
6.5
2021-01-15 CVE-2021-22168 Resource Exhaustion vulnerability in Gitlab
A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.
network
low complexity
gitlab CWE-400
6.5
2021-01-15 CVE-2021-22167 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.1.
network
low complexity
gitlab
7.5
2021-01-15 CVE-2021-22166 Resource Exhaustion vulnerability in Gitlab 13.7.0/13.7.1
An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method
network
low complexity
gitlab CWE-400
7.5
2021-01-15 CVE-2020-26414 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.4.
network
low complexity
gitlab
6.5
2020-12-11 CVE-2020-26411 Improper Resource Shutdown or Release vulnerability in Gitlab
A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2).
network
low complexity
gitlab CWE-404
4.3
2020-12-11 CVE-2020-26417 Information Exposure vulnerability in Gitlab
Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership.
network
low complexity
gitlab CWE-200
5.3