Skip to content
Noroxi

gitlab records

1,481 published records for vendor gitlab.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

1,481 records
  • An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    gitlab · gitlabApr 23, 2021

  • Weak Password Recovery Mechanism for Forgotten Password in GitLab

    CriticalCVSS 9.8KEVWeaponizedEPSS 95%

    gitlab · gitlabJan 12, 2024

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab

    CriticalCVSS 10.0KEVWeaponizedEPSS 91%

    gitlab · gitlabSep 11, 2026

  • When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions

    CriticalCVSS 9.8KEVWeaponizedEPSS 53%

    gitlab · gitlabJun 11, 2021

  • CVE-2021-39935
    71This week

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before

    HighCVSS 7.5KEVWeaponizedEPSS 36%

    gitlab · gitlabDec 13, 2021

  • CVE-2022-2992
    65This week

    A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated us

    CriticalCVSS 9.9WeaponizedEPSS 86%

    gitlab · gitlabOct 17, 2022

  • CVE-2022-2884
    62This week

    A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an auth

    CriticalCVSS 9.9Proof of conceptEPSS 76%

    gitlab · gitlabOct 17, 2022

  • CVE-2022-1162
    62This week

    A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.

    CriticalCVSS 9.8Proof of conceptEPSS 76%

    gitlab · gitlabApr 4, 2022

  • A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 pr

    HighCVSS 8.8Proof of conceptEPSS 77%

    gitlab · gitlabJul 1, 2022

  • An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log

    HighCVSS 8.7No exploitEPSS 69%

    gitlab · gitlabOct 8, 2020

  • Improper Control of Generation of Code ('Code Injection') in GitLab

    CriticalCVSS 9.1Proof of conceptEPSS 60%

    gitlab · gitlabAug 17, 2026

  • GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write ac

    CriticalCVSS 9.8No exploitEPSS 50%

    gitlab · gitlabJul 18, 2018

  • An issue has been discovered in GitLab CE/EE affecting only version 16.0.0.

    HighCVSS 7.5WeaponizedEPSS 72%

    gitlab · gitlabMay 26, 2023

  • An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 befo

    MediumCVSS 5.4No exploitEPSS 96%

    gitlab · gitlabJun 7, 2023

  • An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.

    MediumCVSS 5.4No exploitEPSS 92%

    gitlab · gitlabMar 9, 2023

  • Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versio

    MediumCVSS 6.1Proof of conceptEPSS 82%

    gitlab · gitlabApr 4, 2022

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

    HighCVSS 8.7No exploitEPSS 51%

    gitlab · gitlabFeb 21, 2024

  • Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an atta

    MediumCVSS 5.4No exploitEPSS 87%

    gitlab · gitlabApr 4, 2022

  • A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prio

    MediumCVSS 5.4No exploitEPSS 86%

    gitlab · gitlabNov 9, 2022

  • An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2.

    MediumCVSS 5.3WeaponizedEPSS 80%

    gitlab · gitlabMar 28, 2022

  • An issue has been discovered in GitLab affecting all versions starting with 13.3.

    MediumCVSS 5.4No exploitEPSS 72%

    gitlab · gitlabAug 20, 2021

  • Inefficient Regular Expression Complexity in GitLab

    HighCVSS 7.5No exploitEPSS 44%

    gitlab · gitlabAug 1, 2023

  • An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 befor

    CriticalCVSS 9.8Proof of conceptEPSS 13%

    gitlab · gitlabMar 28, 2022

  • Missing Authorization in GitLab

    CriticalCVSS 9.9No exploitEPSS 12%

    gitlab · gitlabJun 20, 2025

  • Allocation of Resources Without Limits or Throttling in GitLab

    MediumCVSS 4.3No exploitEPSS 84%

    gitlab · gitlabJun 6, 2023