Vulnerabilities > Gitlab > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-07-01 | CVE-2022-2227 | Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions | 3.5 |
2022-06-06 | CVE-2022-1940 | Cross-site Scripting vulnerability in Gitlab A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues | 3.5 |
2022-06-06 | CVE-2022-1783 | Unspecified vulnerability in Gitlab An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. | 2.7 |
2022-05-19 | CVE-2022-1416 | Cross-site Scripting vulnerability in Gitlab Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling | 3.5 |
2022-05-11 | CVE-2022-1124 | Incorrect Authorization vulnerability in Gitlab An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled | 3.5 |
2022-04-11 | CVE-2022-1157 | Information Exposure Through Log Files vulnerability in Gitlab Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged | 3.5 |
2022-04-04 | CVE-2022-1190 | Cross-site Scripting vulnerability in Gitlab Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc. | 3.5 |
2022-04-04 | CVE-2022-1111 | Unspecified vulnerability in Gitlab A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages | 2.7 |
2022-04-01 | CVE-2022-0489 | Resource Exhaustion vulnerability in Gitlab An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . | 3.5 |
2022-03-28 | CVE-2022-0549 | Unspecified vulnerability in Gitlab An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. network gitlab | 3.5 |