Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2023-3399
Disclosure Date: November 06, 2023 (last updated November 15, 2023)
An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD variables using the custom project templates.
0
Attacker Value
Unknown
CVE-2022-2826
Disclosure Date: October 28, 2022 (last updated December 22, 2024)
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. TODO
0
Attacker Value
Unknown
CVE-2021-39897
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the subgroup is transferred
0
Attacker Value
Unknown
CVE-2020-13261
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code
0
Attacker Value
Unknown
CVE-2020-13264
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token
0
Attacker Value
Unknown
CVE-2020-13263
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.
0
Attacker Value
Unknown
CVE-2020-13275
Disclosure Date: June 19, 2020 (last updated November 28, 2024)
A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1
0
Attacker Value
Unknown
CVE-2020-13262
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link
0
Attacker Value
Unknown
CVE-2020-13272
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow
0
Attacker Value
Unknown
CVE-2020-13276
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1
0