Show filters
1,139 Total Results
Displaying 21-30 of 1,139
Sort by:
Attacker Value
Unknown

CVE-2024-10383

Disclosure Date: February 07, 2025 (last updated February 08, 2025)
An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE
0
Attacker Value
Unknown

CVE-2025-1072

Disclosure Date: February 07, 2025 (last updated February 07, 2025)
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. A denial of service could occur upon importing maliciously crafted content using the Fogbugz importer.
0
Attacker Value
Unknown

CVE-2024-2878

Disclosure Date: February 05, 2025 (last updated February 06, 2025)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.
0
Attacker Value
Unknown

CVE-2024-3976

Disclosure Date: February 05, 2025 (last updated February 06, 2025)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unauthorised instance users.
0
Attacker Value
Unknown

CVE-2024-9631

Disclosure Date: February 05, 2025 (last updated February 05, 2025)
An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.
0
Attacker Value
Unknown

CVE-2024-5528

Disclosure Date: February 05, 2025 (last updated February 05, 2025)
An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.
0
Attacker Value
Unknown

CVE-2024-6356

Disclosure Date: February 05, 2025 (last updated February 05, 2025)
An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project access for Security policy bot.
0
Attacker Value
Unknown

CVE-2024-1539

Disclosure Date: February 05, 2025 (last updated February 05, 2025)
An issue has been discovered in GitLab EE affecting all versions starting from 15.2 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose updates to issues to a banned group member using the API.
0
Attacker Value
Unknown

CVE-2023-6386

Disclosure Date: February 05, 2025 (last updated February 05, 2025)
A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike the GitLab instance resource usage resulting in service degradation.
0
Attacker Value
Unknown

CVE-2024-1211

Disclosure Date: January 31, 2025 (last updated January 31, 2025)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 in which cross-site request forgery may have been possible on GitLab instances configured to use JWT as an OmniAuth provider.
0