Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 14.6.4  Security Vulnerabilities
An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.
CVSS Score
5.4
EPSS Score
0.0
Published
2023-05-03
An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates by doing a diff with a pre-existing fork.
CVSS Score
6.5
EPSS Score
0.003
Published
2023-05-03
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.
CVSS Score
4.3
EPSS Score
0.0
Published
2022-10-21
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.
CVSS Score
5.4
EPSS Score
0.002
Published
2022-03-28
A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.
CVSS Score
3.1
EPSS Score
0.002
Published
2022-03-28


Contact Us

Shodan ® - All rights reserved