Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 14.1.4  Security Vulnerabilities
In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from.
CVSS Score
3.7
EPSS Score
0.003
Published
2021-11-05
In all versions of GitLab CE/EE since version 11.10, an admin of a group can see the SCIM token of that group by visiting a specific endpoint.
CVSS Score
2.7
EPSS Score
0.003
Published
2021-11-05
An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request
CVSS Score
4.3
EPSS Score
0.001
Published
2021-11-05
An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with
CVSS Score
4.3
EPSS Score
0.003
Published
2021-11-05
Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.
CVSS Score
8.7
EPSS Score
0.012
Published
2021-11-05
In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings.
CVSS Score
6.5
EPSS Score
0.003
Published
2021-11-04
A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user
CVSS Score
3.1
EPSS Score
0.002
Published
2021-11-04
Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident.
CVSS Score
4.3
EPSS Score
0.002
Published
2021-11-04
In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.
CVSS Score
5.9
EPSS Score
0.001
Published
2021-10-05
In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.
CVSS Score
4.3
EPSS Score
0.001
Published
2021-10-05


Contact Us

Shodan ® - All rights reserved