Vulnerabilities > Gitlab > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-11-10 CVE-2022-3726 Unspecified vulnerability in Gitlab
Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.
network
low complexity
gitlab
critical
9.0
2022-10-28 CVE-2022-2826 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1.
network
low complexity
gitlab
critical
9.8
2022-10-17 CVE-2022-2884 OS Command Injection vulnerability in Gitlab
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint
network
low complexity
gitlab CWE-78
critical
9.9
2022-10-17 CVE-2022-2992 Injection vulnerability in Gitlab
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.
network
low complexity
gitlab CWE-74
critical
9.9
2022-04-04 CVE-2022-1162 Use of Hard-coded Credentials vulnerability in Gitlab
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.
network
low complexity
gitlab CWE-798
critical
9.8
2022-03-28 CVE-2022-0249 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A vulnerability was discovered in GitLab starting with version 12.
network
low complexity
gitlab CWE-918
critical
9.1
2022-03-28 CVE-2022-0735 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2.
network
low complexity
gitlab
critical
9.8
2021-12-06 CVE-2021-39890 Improper Authentication vulnerability in Gitlab
It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.
network
low complexity
gitlab CWE-287
critical
9.8
2021-06-11 CVE-2021-22175 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled
network
low complexity
gitlab CWE-918
critical
9.8
2021-04-23 CVE-2021-22205 Code Injection vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.
network
low complexity
gitlab CWE-94
critical
10.0