Vulnerabilities > Gitlab > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-08-04 CVE-2023-4002 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2.
network
low complexity
gitlab
6.5
2023-08-03 CVE-2023-3932 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2.
network
low complexity
gitlab
6.5
2023-08-02 CVE-2023-2022 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge
network
low complexity
gitlab
4.3
2023-08-02 CVE-2023-3401 Code Injection vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2.
network
low complexity
gitlab CWE-94
6.5
2023-08-02 CVE-2023-3500 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2.
network
low complexity
gitlab CWE-79
6.1
2023-08-02 CVE-2023-1210 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2.
network
low complexity
gitlab
4.3
2023-08-02 CVE-2023-2164 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2.
network
low complexity
gitlab CWE-79
5.4
2023-08-02 CVE-2023-3385 Path Traversal vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 8.10 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2.
network
low complexity
gitlab CWE-22
6.5
2023-07-26 CVE-2023-1401 Exposure of Resource to Wrong Sphere vulnerability in Gitlab 3.1.0/4.0.0
An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.
network
low complexity
gitlab CWE-668
4.3
2023-07-21 CVE-2023-3102 Unspecified vulnerability in Gitlab 16.1.0
A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR.
network
low complexity
gitlab
5.3