Vulnerabilities
Vulnerable Software
Gitlab:  Security Vulnerabilities
For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip.
CVSS Score
7.3
EPSS Score
0.001
Published
2020-08-13
For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.
CVSS Score
6.5
EPSS Score
0.001
Published
2020-08-13
For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.
CVSS Score
3.1
EPSS Score
0.001
Published
2020-08-13
For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title.
CVSS Score
7.3
EPSS Score
0.001
Published
2020-08-13
In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page
CVSS Score
5.5
EPSS Score
0.002
Published
2020-08-12
In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page
CVSS Score
7.5
EPSS Score
0.002
Published
2020-08-12
In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.
CVSS Score
8.1
EPSS Score
0.001
Published
2020-08-12
For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.
CVSS Score
5.4
EPSS Score
0.002
Published
2020-08-10
In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.
CVSS Score
9.6
EPSS Score
0.001
Published
2020-08-10
In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.
CVSS Score
6.3
EPSS Score
0.001
Published
2020-08-10


Contact Us

Shodan ® - All rights reserved