Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 12.7  Security Vulnerabilities
In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
CVSS Score
6.5
EPSS Score
0.002
Published
2021-10-05
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
CVSS Score
5.3
EPSS Score
0.001
Published
2021-10-05
In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.
CVSS Score
4.3
EPSS Score
0.003
Published
2021-10-05
A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.
CVSS Score
5.3
EPSS Score
0.004
Published
2021-10-05
In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.
CVSS Score
5.4
EPSS Score
0.002
Published
2021-10-05
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
CVSS Score
6.5
EPSS Score
0.001
Published
2021-10-05
A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.
CVSS Score
7.3
EPSS Score
0.003
Published
2021-10-05
In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands.
CVSS Score
4.3
EPSS Score
0.003
Published
2021-10-04
A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.
CVSS Score
7.7
EPSS Score
0.002
Published
2021-10-04
Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication
CVSS Score
2.2
EPSS Score
0.001
Published
2021-10-04


Contact Us

Shodan ® - All rights reserved