Skip to main content

Vendor archive

gitlab CVEs

Beta · best-effort

1,421 CVEs tagged to vendor gitlab57 Critical, 294 High, 889 Medium, 180 Low, 1 Unrated.

CVE-2024-9773

Published Mar 27, 2025

An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 befor…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-1257

Published Mar 13, 2025

An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab ins…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-0652

Published Mar 13, 2025

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-8402

Published Mar 13, 2025

An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-7296

Published Mar 13, 2025

An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2 which allowed a user with a custom permissio…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-13054

Published Mar 13, 2025

An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of service vulnerability could allow a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12380

Published Mar 13, 2025

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 bef…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2045

Published Mar 6, 2025

Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-1540

Published Mar 6, 2025

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.…

CVSS 3.1 · Low
evidence mentions
2
Buzz score
25.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-0555

Published Mar 3, 2025

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypa…

CVSS 7.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-0475

Published Mar 3, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially a…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-10925

Published Mar 3, 2025

A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to read Security policy YAML

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8186

Published Mar 3, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could inject HMTL into the chi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3303

Published Feb 13, 2025

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which a…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1198

Published Feb 13, 2025

An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCa…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-8266

Published Feb 13, 2025

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project o…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7102

Published Feb 13, 2025

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circ…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-0516

Published Feb 12, 2025

Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-9870

Published Feb 12, 2025

An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1212

Published Feb 12, 2025

An information disclosure vulnerability in GitLab CE/EE affecting all versions from 8.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1042

Published Feb 12, 2025

An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker…

CVSS 4.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-0376

Published Feb 12, 2025

An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unau…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-12379

Published Feb 12, 2025

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10383

Published Feb 7, 2025

An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versio…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-1072

Published Feb 7, 2025

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. A…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort
Showing 276-300 of 1,421 CVEsPage 12 of 57