Vulnerabilities > Gitlab > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-04-02 CVE-2021-22203 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7.9 before 13.8.7, all versions starting from 13.9 before 13.9.5, and all versions starting from 13.10 before 13.10.1.
network
low complexity
gitlab
critical
9.8
2020-10-07 CVE-2020-13347 Path Traversal vulnerability in Gitlab
A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1.
network
low complexity
gitlab CWE-22
critical
9.1
2020-09-14 CVE-2020-13312 Improper Restriction of Excessive Authentication Attempts vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-307
critical
9.8
2020-09-14 CVE-2020-13300 Incorrect Authorization vulnerability in Gitlab 13.3.0/13.3.1/13.3.2
GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.
network
low complexity
gitlab CWE-863
critical
10.0
2020-08-10 CVE-2020-13292 Improper Authentication vulnerability in Gitlab
In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.
network
low complexity
gitlab CWE-287
critical
9.6
2020-04-08 CVE-2020-10980 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.
network
low complexity
gitlab CWE-918
critical
9.8
2020-03-27 CVE-2020-10956 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.
network
low complexity
gitlab CWE-918
critical
9.8
2020-03-13 CVE-2020-10077 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
GitLab EE 3.0 through 12.8.1 allows SSRF.
network
low complexity
gitlab CWE-918
critical
9.8
2020-03-13 CVE-2020-10074 Unspecified vulnerability in Gitlab
GitLab 10.1 through 12.8.1 has Incorrect Access Control.
network
low complexity
gitlab
critical
9.8
2020-03-13 CVE-2020-10083 Improper Preservation of Permissions vulnerability in Gitlab
GitLab 12.7 through 12.8.1 has Insecure Permissions.
network
low complexity
gitlab CWE-281
critical
9.1