Vulnerabilities > Gitlab > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-10-17 CVE-2022-3330 Unspecified vulnerability in Gitlab
It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.
network
low complexity
gitlab
4.3
2022-10-17 CVE-2022-3331 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.
network
low complexity
gitlab CWE-639
4.3
2022-10-17 CVE-2022-3351 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1.
network
low complexity
gitlab
4.3
2022-08-05 CVE-2022-2095 Incorrect Authorization vulnerability in Gitlab
An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious authenticated user to view a public project's Deploy Key's public fingerprint and name when that key has write permission.
network
low complexity
gitlab CWE-863
4.3
2022-08-05 CVE-2022-2303 Improper Authentication vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab CWE-287
4.3
2022-08-05 CVE-2022-2417 Improper Input Validation vulnerability in Gitlab
Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could be abused in supply chain attacks where a victim pinned to a specific Git commit of the project.
network
low complexity
gitlab CWE-20
4.5
2022-08-05 CVE-2022-2497 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab
6.4
2022-08-05 CVE-2022-2499 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab CWE-639
4.3
2022-08-05 CVE-2022-2500 Cross-site Scripting vulnerability in Gitlab
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1.
network
low complexity
gitlab CWE-79
5.4
2022-08-05 CVE-2022-2512 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab
6.5