
CVE-2022-3758
https://notcve.org/view.php?id=CVE-2022-3758
09 Mar 2023 — An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Due to improper permissions checks an unauthorised user was able to read, add or edit a users private snippet. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3758.json • CWE-276: Incorrect Default Permissions •

CVE-2022-4289
https://notcve.org/view.php?id=CVE-2022-4289
09 Mar 2023 — An issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version 15.9 before 15.9.2. Google IAP details in Prometheus integration were not hidden, could be leaked from instance, group, or project settings to other users. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4289.json •

CVE-2022-4331
https://notcve.org/view.php?id=CVE-2022-4331
09 Mar 2023 — An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previously removed malicious maintainer or owner of the child group can still gain access to the group via SSO or a SCIM token to perform actions on the group. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4331.json • CWE-284: Improper Access Control •

CVE-2022-4007
https://notcve.org/view.php?id=CVE-2022-4007
08 Mar 2023 — A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4007.json • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-4138
https://notcve.org/view.php?id=CVE-2022-4138
13 Feb 2023 — A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4138.json • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2023-0518
https://notcve.org/view.php?id=CVE-2023-0518
13 Feb 2023 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. It was possible to trigger a DoS attack by uploading a malicious Helm chart. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0518.json • CWE-400: Uncontrolled Resource Consumption •

CVE-2022-3411
https://notcve.org/view.php?id=CVE-2022-3411
13 Feb 2023 — A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3411.json • CWE-400: Uncontrolled Resource Consumption CWE-1284: Improper Validation of Specified Quantity in Input •

CVE-2022-3759
https://notcve.org/view.php?id=CVE-2022-3759
13 Feb 2023 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. An attacker may upload a crafted CI job artifact zip file in a project that uses dynamic child pipelines and make a sidekiq job allocate a lot of memory. In GitLab instances where Sidekiq is memory-limited, this may cause Denial of Service. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3759.json • CWE-400: Uncontrolled Resource Consumption •

CVE-2022-4201
https://notcve.org/view.php?id=CVE-2022-4201
27 Jan 2023 — A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to local addresses when configuring a malicious GitLab Runner. Un blind SSRF en GitLab CE/EE que afecta a todas las versiones 11.3 anteriores a 15.4.6, 15.5 anteriores a 15.5.5 y 15.6 anteriores a 15.6.1 permite a un atacante conectarse a direcciones locales al configurar un GitLab Runner malicioso. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4201.json • CWE-918: Server-Side Request Forgery (SSRF) •

CVE-2022-4205
https://notcve.org/view.php?id=CVE-2022-4205
27 Jan 2023 — In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash. En Gitlab EE/CE anterior a 15.6.1, 15.5.5 y 15.4.6, el uso de una rama con un nombre hexadecimal podía anular un hash existente. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4205.json • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •