Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 14.10.4  Security Vulnerabilities
Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link
CVSS Score
8.7
EPSS Score
0.046
Published
2022-07-01
An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.
CVSS Score
5.0
EPSS Score
0.002
Published
2022-07-01
An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows project memebers with reporter role to manage issues in project's error tracking feature.
CVSS Score
4.3
EPSS Score
0.002
Published
2022-07-01
An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.
CVSS Score
2.6
EPSS Score
0.003
Published
2022-07-01


Contact Us

Shodan ® - All rights reserved