Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  Security Vulnerabilities
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 where an infinite loop exist when an authenticated user with specific rights access a MR having source and target branch pointing to each other
CVSS Score
3.5
EPSS Score
0.004
Published
2021-04-02
An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects.
CVSS Score
4.3
EPSS Score
0.003
Published
2021-04-02
An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an internal repository through a public project fork as an anonymous user.
CVSS Score
5.9
EPSS Score
0.002
Published
2021-04-02
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server.
CVSS Score
9.6
EPSS Score
0.09
Published
2021-04-02
Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.
CVSS Score
4.3
EPSS Score
0.002
Published
2021-04-01
Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page
CVSS Score
4.3
EPSS Score
0.003
Published
2021-03-26
An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.
CVSS Score
4.3
EPSS Score
0.001
Published
2021-03-26
An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.
CVSS Score
6.2
EPSS Score
0.001
Published
2021-03-26
In all versions of GitLab, marshalled session keys were being stored in Redis.
CVSS Score
5.7
EPSS Score
0.0
Published
2021-03-26
An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.
CVSS Score
4.3
EPSS Score
0.002
Published
2021-03-24


Contact Us

Shodan ® - All rights reserved