Vulnerabilities > Gitlab > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-10-17 CVE-2022-2592 Improper Validation of Specified Quantity in Input vulnerability in Gitlab
A lack of length validation in Snippet descriptions in GitLab CE/EE affecting all versions prior to 15.1.6, 15.2 prior to 15.2.4 and 15.3 prior to 15.3.2 allows an authenticated attacker to create a maliciously large Snippet which when requested with or without authentication places excessive load on the server, potential leading to Denial of Service.
network
low complexity
gitlab CWE-1284
6.5
2022-10-17 CVE-2022-2630 Unspecified vulnerability in Gitlab
An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events.
network
low complexity
gitlab
4.3
2022-10-17 CVE-2022-2865 Cross-site Scripting vulnerability in Gitlab
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2.
network
low complexity
gitlab CWE-79
4.8
2022-10-17 CVE-2022-2908 Unspecified vulnerability in Gitlab
A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a special crafted input added in the Commit message field.
network
low complexity
gitlab
4.3
2022-10-17 CVE-2022-3030 Unspecified vulnerability in Gitlab
An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.
network
low complexity
gitlab
4.3
2022-10-17 CVE-2022-3066 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1.
network
low complexity
gitlab
5.4
2022-10-17 CVE-2022-3067 Unspecified vulnerability in Gitlab
An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1.
network
low complexity
gitlab
6.5
2022-10-17 CVE-2022-3279 Improper Handling of Exceptional Conditions vulnerability in Gitlab
An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs
network
low complexity
gitlab CWE-755
6.5
2022-10-17 CVE-2022-3286 Unspecified vulnerability in Gitlab
Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token
network
low complexity
gitlab
5.3
2022-10-17 CVE-2022-3288 Unspecified vulnerability in Gitlab
A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.
network
low complexity
gitlab
4.3