Vulnerabilities > Gitlab > Low

DATE CVE VULNERABILITY TITLE RISK
2022-07-01 CVE-2022-2227 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions
network
gitlab CWE-732
3.5
2022-06-06 CVE-2022-1940 Cross-site Scripting vulnerability in Gitlab
A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues
network
gitlab CWE-79
3.5
2022-06-06 CVE-2022-1783 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1.
network
low complexity
gitlab
2.7
2022-05-19 CVE-2022-1416 Cross-site Scripting vulnerability in Gitlab
Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling
network
gitlab CWE-79
3.5
2022-05-11 CVE-2022-1124 Incorrect Authorization vulnerability in Gitlab
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled
network
gitlab CWE-863
3.5
2022-04-11 CVE-2022-1157 Information Exposure Through Log Files vulnerability in Gitlab
Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged
network
gitlab CWE-532
3.5
2022-04-04 CVE-2022-1190 Cross-site Scripting vulnerability in Gitlab
Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.
network
gitlab CWE-79
3.5
2022-04-04 CVE-2022-1111 Unspecified vulnerability in Gitlab
A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages
network
low complexity
gitlab
2.7
2022-04-01 CVE-2022-0489 Resource Exhaustion vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 .
network
gitlab CWE-400
3.5
2022-03-28 CVE-2022-0549 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
network
gitlab
3.5