Vulnerabilities > Gitlab > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-07-21 CVE-2023-3484 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2.
network
low complexity
gitlab
6.5
2023-07-13 CVE-2023-2200 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML in an email address field.
network
low complexity
gitlab CWE-79
5.4
2023-07-13 CVE-2023-2576 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1.
network
low complexity
gitlab
4.3
2023-07-13 CVE-2023-3362 Improper Authentication vulnerability in Gitlab 16.1.0
An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.
network
low complexity
gitlab CWE-287
5.3
2023-07-13 CVE-2023-3444 Injection vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches.
network
low complexity
gitlab CWE-74
6.5
2023-07-13 CVE-2023-2190 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1.
network
low complexity
gitlab CWE-639
6.5
2023-07-11 CVE-2023-1936 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a service desk issue.
network
low complexity
gitlab
4.3
2023-06-28 CVE-2022-4143 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization
network
high complexity
gitlab CWE-367
5.3
2023-06-28 CVE-2023-2232 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira prefix
network
low complexity
gitlab
6.5
2023-06-07 CVE-2023-0508 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2.
network
low complexity
gitlab
4.3