
CVE-2023-1265
https://notcve.org/view.php?id=CVE-2023-1265
03 May 2023 — An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1265.json • CWE-384: Session Fixation •

CVE-2023-2182
https://notcve.org/view.php?id=CVE-2023-2182
03 May 2023 — An issue has been discovered in GitLab EE affecting all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions when OpenID Connect is enabled on an instance, it may allow users who are marked as 'external' to become 'regular' users thus leading to privilege escalation for those users. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2182.json •

CVE-2023-0805
https://notcve.org/view.php?id=CVE-2023-0805
03 May 2023 — An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to have access to the public projects of a public group even after being banned from the public group by the owner. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0805.json • CWE-862: Missing Authorization •

CVE-2023-1710
https://notcve.org/view.php?id=CVE-2023-1710
05 Apr 2023 — A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to 15.10.1 allows an attacker to view the count of internal notes for a given issue. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1710.json • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2023-0450
https://notcve.org/view.php?id=CVE-2023-0450
05 Apr 2023 — An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. It was possible to add a branch with an ambiguous name that could be used to social engineer users. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0450.json •

CVE-2022-3375
https://notcve.org/view.php?id=CVE-2022-3375
05 Apr 2023 — An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible to disclose the branch names when attacker has a fork of a project that was switched to private. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3375.json • CWE-535: Exposure of Information Through Shell Error Message •

CVE-2023-1417
https://notcve.org/view.php?id=CVE-2023-1417
05 Apr 2023 — An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1417.json • CWE-639: Authorization Bypass Through User-Controlled Key CWE-863: Incorrect Authorization •

CVE-2023-1787
https://notcve.org/view.php?id=CVE-2023-1787
05 Apr 2023 — An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A search timeout could be triggered if a specific HTML payload was used in the issue description. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1787.json • CWE-400: Uncontrolled Resource Consumption •

CVE-2023-1071
https://notcve.org/view.php?id=CVE-2023-1071
05 Apr 2023 — An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1071.json • CWE-400: Uncontrolled Resource Consumption CWE-863: Incorrect Authorization •

CVE-2022-3513
https://notcve.org/view.php?id=CVE-2022-3513
05 Apr 2023 — An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A specially crafted payload could lead to a reflected XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims on self-hosted instances running without strict CSP. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3513.json • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •