Show filters
1,139 Total Results
Displaying 31-40 of 1,139
Sort by:
Attacker Value
Unknown

CVE-2023-6195

Disclosure Date: January 31, 2025 (last updated January 31, 2025)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown image value when importing a GitHub repository.
0
Attacker Value
Unknown

CVE-2025-0290

Disclosure Date: January 28, 2025 (last updated January 28, 2025)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 prior to 17.5.5, from 17.6 prior to 17.6.3, and from 17.7 prior to 17.7.1. Under certain conditions, processing of CI artifacts metadata could cause background jobs to become unresponsive.
0
Attacker Value
Unknown

CVE-2025-0314

Disclosure Date: January 24, 2025 (last updated January 24, 2025)
An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site scripting.
0
Attacker Value
Unknown

CVE-2024-11931

Disclosure Date: January 24, 2025 (last updated January 24, 2025)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint.
0
Attacker Value
Unknown

CVE-2024-13041

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external provider configuration. As a result, the user may not be marked as external thereby giving those users access to internal projects or groups.
0
Attacker Value
Unknown

CVE-2024-6324

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics.
0
Attacker Value
Unknown

CVE-2024-12431

Disclosure Date: January 08, 2025 (last updated January 09, 2025)
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects.
0
Attacker Value
Unknown

CVE-2025-0194

Disclosure Date: January 08, 2025 (last updated January 09, 2025)
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. Under certain conditions, access tokens may have been logged when API requests were made in a specific manner.
0
Attacker Value
Unknown

CVE-2023-5117

Disclosure Date: December 25, 2024 (last updated January 05, 2025)
An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.
0
Attacker Value
Unknown

CVE-2024-8650

Disclosure Date: December 16, 2024 (last updated December 18, 2024)
An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.
0