Vulnerabilities
Vulnerable Software
Gitlab:  Security Vulnerabilities
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the GraphQL api allowed a maintainer to delete a repository.
CVSS Score
6.5
EPSS Score
0.002
Published
2020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.
CVSS Score
5.4
EPSS Score
0.003
Published
2020-09-14
A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.
CVSS Score
6.4
EPSS Score
0.001
Published
2020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token
CVSS Score
6.5
EPSS Score
0.002
Published
2020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues
CVSS Score
4.3
EPSS Score
0.003
Published
2020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.
CVSS Score
5.4
EPSS Score
0.002
Published
2020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.
CVSS Score
8.1
EPSS Score
0.002
Published
2020-09-14
GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.
CVSS Score
8.0
EPSS Score
0.002
Published
2020-09-14
For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature
CVSS Score
6.5
EPSS Score
0.001
Published
2020-08-13
For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.
CVSS Score
6.4
EPSS Score
0.001
Published
2020-08-13


Contact Us

Shodan ® - All rights reserved