Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 4.3.0  Security Vulnerabilities
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.
CVSS Score
6.5
EPSS Score
0.003
Published
2022-01-18
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.
CVSS Score
3.5
EPSS Score
0.003
Published
2022-01-18
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.
CVSS Score
4.3
EPSS Score
0.003
Published
2022-01-18
A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances
CVSS Score
5.9
EPSS Score
0.002
Published
2021-12-13
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges
CVSS Score
4.4
EPSS Score
0.001
Published
2021-11-05
In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
CVSS Score
6.5
EPSS Score
0.002
Published
2021-10-05
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
CVSS Score
6.5
EPSS Score
0.002
Published
2021-10-05
In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.
CVSS Score
5.3
EPSS Score
0.003
Published
2021-10-05
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
CVSS Score
5.3
EPSS Score
0.001
Published
2021-10-05
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
CVSS Score
5.4
EPSS Score
0.003
Published
2021-10-05


Contact Us

Shodan ® - All rights reserved