
CVE-2019-14944
https://notcve.org/view.php?id=CVE-2019-14944
15 Apr 2023 — An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution. • https://about.gitlab.com/blog/categories/releases • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2018-15472
https://notcve.org/view.php?id=CVE-2018-15472
15 Apr 2023 — An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter using rouge can block for a long time in Sidekiq jobs without any timeout. • https://about.gitlab.com/blog/categories/releases • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2023-1710
https://notcve.org/view.php?id=CVE-2023-1710
05 Apr 2023 — A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to 15.10.1 allows an attacker to view the count of internal notes for a given issue. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1710.json •

CVE-2022-3375
https://notcve.org/view.php?id=CVE-2022-3375
05 Apr 2023 — An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible to disclose the branch names when attacker has a fork of a project that was switched to private. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3375.json •

CVE-2023-1787
https://notcve.org/view.php?id=CVE-2023-1787
05 Apr 2023 — An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A search timeout could be triggered if a specific HTML payload was used in the issue description. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1787.json •

CVE-2023-0523
https://notcve.org/view.php?id=CVE-2023-0523
05 Apr 2023 — An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0523.json • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-1708
https://notcve.org/view.php?id=CVE-2023-1708
05 Apr 2023 — An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1708.json • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2023-1167
https://notcve.org/view.php?id=CVE-2023-1167
05 Apr 2023 — Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1167.json • CWE-862: Missing Authorization •

CVE-2023-1071
https://notcve.org/view.php?id=CVE-2023-1071
05 Apr 2023 — An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1071.json • CWE-863: Incorrect Authorization •

CVE-2023-1733
https://notcve.org/view.php?id=CVE-2023-1733
05 Apr 2023 — A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1733.json •