Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 14.7  Security Vulnerabilities
An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.
CVSS Score
5.4
EPSS Score
0.0
Published
2023-05-03
An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates by doing a diff with a pre-existing fork.
CVSS Score
6.5
EPSS Score
0.003
Published
2023-05-03
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.
CVSS Score
4.3
EPSS Score
0.0
Published
2022-10-21
A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.
CVSS Score
3.1
EPSS Score
0.002
Published
2022-03-28
An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.
CVSS Score
4.7
EPSS Score
0.001
Published
2022-03-28


Contact Us

Shodan ® - All rights reserved