Vulnerabilities > Gitlab > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-06-08 CVE-2021-22220 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting with 13.10.
network
low complexity
gitlab CWE-79
5.4
2021-06-08 CVE-2021-22213 Unspecified vulnerability in Gitlab
A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari
network
low complexity
gitlab
6.5
2021-06-08 CVE-2021-22217 Unspecified vulnerability in Gitlab
A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request
network
low complexity
gitlab
6.5
2021-06-08 CVE-2021-22219 Information Exposure Through Log Files vulnerability in Gitlab
All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.
network
low complexity
gitlab CWE-532
4.9
2021-06-08 CVE-2021-22221 Insufficient Session Expiration vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2.
network
low complexity
gitlab CWE-613
6.5
2021-05-06 CVE-2021-22206 Cleartext Storage of Sensitive Information vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 11.6.
network
low complexity
gitlab CWE-312
4.9
2021-05-06 CVE-2021-22208 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting versions starting with 13.5 up to 13.9.7.
network
low complexity
gitlab
4.3
2021-05-06 CVE-2021-22210 Allocation of Resources Without Limits or Throttling vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2.
network
low complexity
gitlab CWE-770
5.3
2021-05-06 CVE-2021-22211 Incorrect Authorization vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7.
network
low complexity
gitlab CWE-863
4.3
2021-04-22 CVE-2021-22199 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting with 12.9.
network
low complexity
gitlab CWE-79
5.4