Vulnerabilities > Gitlab

DATE CVE VULNERABILITY TITLE RISK
2023-09-01 CVE-2023-3950 Cleartext Storage of Sensitive Information vulnerability in Gitlab
An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured.
network
low complexity
gitlab CWE-312
3.8
2023-09-01 CVE-2023-4018 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1.
network
low complexity
gitlab
5.3
2023-09-01 CVE-2023-4378 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1.
network
low complexity
gitlab
4.3
2023-09-01 CVE-2023-4647 Resource Exhaustion vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.
network
low complexity
gitlab CWE-400
7.5
2023-08-30 CVE-2023-4522 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions before 16.2.0.
network
low complexity
gitlab
5.3
2023-08-04 CVE-2023-4002 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2.
network
low complexity
gitlab
6.5
2023-08-03 CVE-2023-4008 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2.
network
low complexity
gitlab
critical
9.8
2023-08-03 CVE-2023-3932 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2.
network
low complexity
gitlab
6.5
2023-08-02 CVE-2023-2022 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge
network
low complexity
gitlab
4.3
2023-08-02 CVE-2023-3401 Code Injection vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2.
network
low complexity
gitlab CWE-94
6.5