Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 14.6.2  Security Vulnerabilities
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.
CVSS Score
10.0
EPSS Score
0.311
Published
2022-03-28
An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. GitLab was leaking user passwords when adding mirrors with SSH credentials under specific conditions.
CVSS Score
4.2
EPSS Score
0.002
Published
2022-03-28
Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleading content which could trick unsuspecting users into executing arbitrary commands
CVSS Score
6.5
EPSS Score
0.003
Published
2022-03-28
An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.
CVSS Score
8.6
EPSS Score
0.003
Published
2022-01-18
Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and between 14.6.0 and 14.6.1 would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configured to run on a port other than 80 or 443
CVSS Score
3.5
EPSS Score
0.001
Published
2022-01-18


Contact Us

Shodan ® - All rights reserved