Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 14.9.0  Security Vulnerabilities
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts
CVSS Score
9.1
EPSS Score
0.881
Published
2022-04-04
A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.
CVSS Score
4.3
EPSS Score
0.004
Published
2022-04-04


Contact Us

Shodan ® - All rights reserved