Vulnerabilities > Gitlab > High

DATE CVE VULNERABILITY TITLE RISK
2022-05-11 CVE-2022-1510 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
low complexity
gitlab
7.5
2022-04-04 CVE-2022-1174 Improper Validation of Specified Quantity in Input vulnerability in Gitlab
A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.
network
low complexity
gitlab CWE-1284
7.5
2022-04-01 CVE-2021-39908 Code Injection vulnerability in Gitlab
In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.
network
low complexity
gitlab CWE-94
7.5
2022-04-01 CVE-2022-0425 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.
network
low complexity
gitlab CWE-918
7.6
2022-04-01 CVE-2022-0741 Improper Encoding or Escaping of Output vulnerability in Gitlab
Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables via specially crafted email addresses.
network
low complexity
gitlab CWE-116
7.5
2022-03-28 CVE-2022-0136 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1.
network
low complexity
gitlab CWE-918
8.1
2022-03-28 CVE-2022-0427 Cross-Site Request Forgery (CSRF) vulnerability in Gitlab
Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover
network
low complexity
gitlab CWE-352
8.8
2022-03-28 CVE-2022-0738 Insufficiently Protected Credentials vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2.
network
low complexity
gitlab CWE-522
7.5
2022-03-28 CVE-2022-0751 Unspecified vulnerability in Gitlab
Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleading content which could trick unsuspecting users into executing arbitrary commands
network
low complexity
gitlab
8.8
2022-01-18 CVE-2022-0154 Cross-Site Request Forgery (CSRF) vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2.
network
low complexity
gitlab CWE-352
8.0