746 results (0.004 seconds)

CVSS: 5.8EPSS: %CPEs: 3EXPL: 1

27 Aug 2025 — An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API. • https://gitlab.com/gitlab-org/gitlab/-/issues/524592 • CWE-862: Missing Authorization •

CVSS: 6.8EPSS: %CPEs: 3EXPL: 1

27 Aug 2025 — An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have could have allowed an authenticated user to cause a Denial of Service (DoS) condition by submitting URLs that generate excessively large responses. • https://gitlab.com/gitlab-org/gitlab/-/issues/536034 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVSS: 5.0EPSS: %CPEs: 3EXPL: 1

27 Aug 2025 — An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by taking advantage of ambiguity between branches and tags during repository imports. • https://gitlab.com/gitlab-org/gitlab/-/issues/545165 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 6.8EPSS: 0%CPEs: 3EXPL: 1

13 Aug 2025 — An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted payloads to specific integration API endpoints. • https://gitlab.com/gitlab-org/gitlab/-/issues/520353 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVSS: 3.1EPSS: 0%CPEs: 3EXPL: 1

13 Aug 2025 — An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions. • https://gitlab.com/gitlab-org/gitlab/-/issues/525515 • CWE-1220: Insufficient Granularity of Access Control •

CVSS: 6.8EPSS: 0%CPEs: 3EXPL: 1

13 Aug 2025 — An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an authenticated user to cause a denial of service condition by creating specially crafted content that consumes excessive server resources when processed. • https://gitlab.com/gitlab-org/gitlab/-/issues/526349 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVSS: 6.8EPSS: 0%CPEs: 3EXPL: 1

13 Aug 2025 — An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending specially crafted markdown payloads to the Wiki feature. • https://gitlab.com/gitlab-org/gitlab/-/issues/528995 • CWE-1333: Inefficient Regular Expression Complexity •

CVSS: 4.3EPSS: 0%CPEs: 3EXPL: 1

10 Jul 2025 — An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass group-level forking restrictions by manipulating API requests. • https://gitlab.com/gitlab-org/gitlab/-/issues/534636 • CWE-863: Incorrect Authorization •

CVSS: 6.8EPSS: 0%CPEs: 3EXPL: 1

26 Jun 2025 — An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests. • https://gitlab.com/gitlab-org/gitlab/-/issues/534424 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVSS: 9.0EPSS: 0%CPEs: 3EXPL: 1

20 Jun 2025 — A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page. • https://gitlab.com/gitlab-org/gitlab/-/issues/457474 • CWE-1333: Inefficient Regular Expression Complexity •